This report analyzes campaigns by the Turla Group, focusing on malware samples, indicators of compromise (IOCs), and detection resources. It includes YARA and Sigma rules to identify Turla-related artifacts and provides information on the countries and sectors where the group’s malicious activity has been observed. Supported by credible sources, the analysis offers valuable insights into the group’s operations. It is not an in-depth analysis of Turla tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.
Turla is a highly advanced cyber espionage group that has been active since at least 2004. It is known for targeting government, diplomatic, military, and research sectors worldwide. The group employs custom tools and sophisticated tactics to conduct surveillance, exfiltrate sensitive data, and maintain long-term access to high-value targets. Turla’s operations are characterized by precision, innovation, and a focus on strategic objectives.
Russia
Espionage
2004
It collects system information, communicates with a hard-coded C2 server on port 9443, and installs additional malware on compromised devices.
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
destinationPort:"9443" and threatName:"Turla"
dbbf8108fd14478ae05d3a3a6aabc242bff6af6eb1e93cbead4f5a23c3587cedSHA-256: 267071df79927abd1e57f57106924dd8a68e1c4ed74e7b69403cdcdf6e6a453b
Sample: ANY.RUN
SHA-256: d6ac21a409f35a80ba9ccfe58ae1ae32883e44ecc724e4ae8289e7465ab2cf40
Sample: ANY.RUN
SHA-256: e2d033b324450e1cb7575fedfc784e66488e342631f059988a9a2fd6e006d381
Sample: ANY.RUN
SHA-256: 0E8CEDF69E0708F77B8D8C7C9B96BF9386F0EC66C48B973BFA9718915ED260E9
Sample: ANY.RUN
CrimsonRAT communicates with a C2 server at Contabo ur253.duckdns[.]org, which is used by Turla's infrastructure to deploy tools such as the clipboard monitor tool. This facilitates management and data transmission between infected devices and Turla's infrastructure.
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
domainName:"ur253.duckdns.org"
aba8b59281faa8c1c43a4ca7af075edd3e3516d3cef058a1f43b093177b8f83cSHA-256: e298b83891b192b8a2782e638e7f5601acf13bab2f619215ac68a0b61230a273
Sample: ANY.RUN
Pelmeni Wrapper: New Wrapper of Kazuar
15f5e4808549ff67a79f84e23659da912ebbc1dc7c7b100c12b72384a27e412a7ae9768b79a6b75f814a1b7afaf841b1a4b7ba803b3d806823e81d24a84fd078cccd6327dd5beee19cc3744b40f954c84ab016564b896c257f6871043a21cf0a6559d6cb2976334776ded3e7f8ce781c0e6fbaa69edbb0f16b902d06b5d8d8d92164d54c415b48e906ad972a14d45c82af7cab814c6cf11729a994249690ed97564b2a3083e55933e4ce68b87c5e268c88d58f7ab41839e5a6e0c728a58e9cf200256c7fd9a36c6a4805c467b15b3a72dbac2e6dbd12abe7d768f20ce6c8f09f1a3cc19345737bc76bcf61005ad6afeeea78540bddc627db052cede7a4c0d8e5ebf10222bdd19bd8f14b7e94694c1534d4fe1d1047034aee7ffe9492cad4a92fc91891c297971f46c470ea3b1934e5fb76f683776ba3edcdc1afe4f5398fc0169b97e740b65bc609210f095cd9407c990a9f71f580f001ea07300228c5256d620e8cedf69e0708f77b8d8c7c9b96bf9386f0ec66c48b973bfa9718915ed260e9hxxps[:]//altavista.rs/wp-includes/ID3/PerceptionSimulation/hxxps[:]//m6front.sam-maintenance.com/wp-includes/customize/assembly/hxxps[:]//bibliotecaunicef.uy/catalog/notices/tags/wss[:]//127.0.0.1:20089/TestTurla’s New Backdoor Targeting Polish NGOs
267071df79927abd1e57f57106924dd8a68e1c4ed74e7b69403cdcdf6e6a453bd6ac21a409f35a80ba9ccfe58ae1ae32883e44ecc724e4ae8289e7465ab2cf40ad4d196b3d85d982343f32d52bffc6ebfeec7bf30553fa441fd7c3ae495075fc13c017cb706ef869c061078048e550dba1613c0f2e8f2e409d97a1c0d9949346b376a3a6bae73840e70b2fa3df99d881def9250b42b6b8b0458d0445ddfbc044hanagram[.]jpthefinetreats[.]comcaduff-sa[.]chjeepcarlease[.]combuy-new-car[.]comcarleasingguru[.]com91[.]193.18.120Secret Blizzard compromising Storm-0156
The Invisible Hand of Secret Blizzard
e298b83891b192b8a2782e638e7f5601acf13bab2f619215ac68a0b61230a27308803510089c8832df3f6db57aded7bfd2d91745e7dd44985d4c9cb9bd5fd1d2aba8b59281faa8c1c43a4ca7af075edd3e3516d3cef058a1f43b093177b8f83c7c4ef30bd1b5cb690d2603e33264768e3b42752660c79979a5db80816dfb2ad2dbbf8108fd14478ae05d3a3a6aabc242bff6af6eb1e93cbead4f5a23c3587ced7c7fad6b9ecb1e770693a6c62e0cc4183f602b892823f4a451799376be915912e2d033b324450e1cb7575fedfc784e66488e342631f059988a9a2fd6e006d381C039ec6622393f9324cacbf8cfaba3b7a41fe6929812ce3bd5d79b0fdedc884a59d7ec6ec97c6b958e00a3352d38dd13876fecdb2bb13a8541ab93248edde317connectotels[.]nethostelhotels[.]net94.177.198[.]94162.213.195[.]12946.249.58[.]20195.111.229[.]253146.70.158[.]90143.198.73[.]108161.35.192[.]20791.234.33[.]48154.53.42[.]19438.242.207[.]36167.86.118[.]69164.68.108[.]153144.91.72[.]17130.185.119[.]198176.57.184[.]97173.212.252[.]2209.126.11[.]25145.14.194[.]25337.60.236[.]1865.189.183[.]63109.123.244[.]46146.70.81[.]81162.213.195[.]192154.53.42[.]19466.219.22[.]25266.219.22[.]102144.126.152[.]205185.229.119[.]60209.126.6[.]227209.126.81[.]42209.126.7[.]8154.38.160[.]218144.126.154[.]84185.213.27[.]94167.86.113[.]24123.88.26[.]187173.249.7[.]11162.171.153[.]221149.102.140[.]36173.249.18[.]25184.247.181[.]6438.242.219[.]1362.171.153[.]22138.242.211[.]8745.14.194[.]253173.212.206[.]227209.145.52[.]172Turla: A Master’s Art of Evasion
cac4d4364d20fa343bf681f6544b31995a57d8f69ee606c4675db60be5ae8775c2618fb013135485f9f9aa27983df3371dfdcb7beecde86d02cee0c258d5ed7fb6abbeab6e000036c6cdffc57c096d796397263e280ea264eba73ac5bab394417091ce97fb5906680c1b09558bafdf9681a81f5f524677b90fd0f7fc0a05bc00hxxps://ies.inquirer.com.ph/advprod03/assets/images/Advisory23-UCDMS04-11-01.zipfiles.philbendeck.comb4db8e598741193ea9e04c2111d0c15ba79b2fa098efc3680a63ef457e60dbd96829ab9c4c8a9a0212740f46bf93b1cbe5d4256fb4ff66d65a3a6eb6c55758a18c97df4ca1a5995e22c2c4887bea2945269d6f5f158def98d5ebdd5311bb20c476629afb86bd9024c3ea6759eeea197ba6c8c780e0041d1f8182d206cf3bd1b4TURLA’s campaign in Eastern Europe
45.153.241[.]16279.110.52[.]218149.154.157[.]11baltdefcol.webredirect[.]orgwkoinfo.webredirect[.]orgjadlactnato.webredirect[.]orgf6e755e2af0231a614975d64ea3c8116f223e046dd4e3f98bfeb1263a78ff080Turla Technical Analysis Report
rule TinyTurlaNG {
meta:
date = "18.04.2024"
author = "Bilal BAKARTEPE"
hash = "0f2e9f501ca9780eff309b7022c9b01a"
strings:
$pwshll_command_1 = "Set-PSReadLineOption -HistorySaveStyle SaveNothing"
$pwshll_command_2 = "chcp 437 > $null"
$c2_command_1 = "timeout"
$c2_command_2 = "killme"
$c2_command_3 = "changeshell"
$c2_command_4 = "changepoint"
$c2_command_5 = "get"
$c2_command_6 = "post"
condition:
all of them
}
TinyTurla - Turla deploys new malware
import "pe"
rule TinyTurla {
meta:
author = "Cisco Talos"
description = "Detects Tiny Turla backdoor DLL"
strings:
$a = "Title:" fullword wide
$b = "Hosts" fullword wide
$c = "Security" fullword wide
$d = "TimeLong" fullword wide
$e = "TimeShort" fullword wide
$f = "MachineGuid" fullword wide
$g = "POST" fullword wide
$h = "WinHttpSetOption" fullword ascii
$i = "WinHttpQueryDataAvailable" fullword ascii
condition:
pe.is_pe and
pe.characteristics & pe.DLL and
pe.exports("ServiceMain") and
all of them
}
rule Tiny_Backdoor {
meta:
author = "Cyble Research and Intelligence Labs"
description = "Detects Malicious MSBuild Project file used in this campaign"
date = "2024-05-20"
os = "Windows"
strings:
$a1 = "[<shell>]" ascii wide
$a2 = "[<sleep>]" ascii wide
$a3 = "[<upload>]" ascii wide
$a4 = "[<download>]" ascii wide
$a5 = "?m=c&id=" ascii wide fullword
condition:
all of them
}
Turla Technical Analysis Report
title: C2 Communication for TinyTurla-NG
description: Detects communication with the command and control server
author: Bilal Bakartepe
date: 2024/04/18
status: experimental
logsource:
product: windows
category: network_connection
detection:
selectionURL:
cs-uri|contains:
- "https://jeepcarlease.com/wp-includes/blocks/rss.old.php"
- "https://caduff-sa.ch/wp-includes/blocks/rss.old.php"
- "hanagram.jp"
- "buy-new-car.com"
- "thefinetreats.com"
- "carleasingguru.com"
condition: selectionURL
falsepositives:
- Unknown
level: high