logo

Turla__2016__Report_Ruag-Espionage-Case.pdf

ID: e1d3497c-d76a-4dcc-ab34-b40ffec3c646

STIX ID: report--e1d3497c-d76a-4dcc-ab34-b40ffec3c646

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2016-05-19

Last Modified Date: 2016-05-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
GovCERT's RUAG Technical Report analyzes a long-running cyber espionage operation attributed to the Turla/Tavdig actor group, describing recon tools and stage-2 trojans, the use of Carbon-DLL and Tavdig, a hierarchical botnet, communication via named pipes and HTTP-based C2, extensive fingerprinting and information gathering, persistence and lateral movement within Active Directory, data exfiltration of approximately 23 GB, and comprehensive recommendations across system, AD, and network controls to detect and mitigate such attacks.