Turla Attacks

Overview

This report analyzes campaigns by the Turla Group, focusing on malware samples, indicators of compromise (IOCs), and detection resources. It includes YARA and Sigma rules to identify Turla-related artifacts and provides information on the countries and sectors where the group’s malicious activity has been observed. Supported by credible sources, the analysis offers valuable insights into the group’s operations. It is not an in-depth analysis of Turla tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.

About Turla

Turla is a highly advanced cyber espionage group that has been active since at least 2004. It is known for targeting government, diplomatic, military, and research sectors worldwide. The group employs custom tools and sophisticated tactics to conduct surveillance, exfiltrate sensitive data, and maintain long-term access to high-value targets. Turla’s operations are characterized by precision, innovation, and a focus on strategic objectives.

Origin Country

Russia

Motivation

Espionage

First Seen

2004

Targeted Countries

  • Afghanistan
  • Austria
  • Estonia
  • India
  • Philippines
  • Poland
  • Ukraine

TwoDash

  • Secret Blizzard compromising Storm-0156
  • The Invisible Hand of Secret Blizzard

It collects system information, communicates with a hard-coded C2 server on port 9443, and installs additional malware on compromised devices.

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: destinationPort:"9443" and threatName:"Turla"

  • SHA-256: dbbf8108fd14478ae05d3a3a6aabc242bff6af6eb1e93cbead4f5a23c3587ced
  • Sample: ANY.RUN

TinyTurla

  • Cisco Talos Report #1: TinyTurla Analysis

  • Cisco Talos Report #2: TinyTurla Analysis

  • Cisco Talos Report #3: TinyTurla Analysis

  • SHA-256: 267071df79927abd1e57f57106924dd8a68e1c4ed74e7b69403cdcdf6e6a453b

  • Sample: ANY.RUN

  • SHA-256: d6ac21a409f35a80ba9ccfe58ae1ae32883e44ecc724e4ae8289e7465ab2cf40

  • Sample: ANY.RUN

  • SHA-256: e2d033b324450e1cb7575fedfc784e66488e342631f059988a9a2fd6e006d381

  • Sample: ANY.RUN


Kazuar

  • Upgraded Kazuar, Unit42

  • SHA-256: 0E8CEDF69E0708F77B8D8C7C9B96BF9386F0EC66C48B973BFA9718915ED260E9

  • Sample: ANY.RUN


CrimsonRAT

  • Secret Blizzard compromising Storm-0156

CrimsonRAT communicates with a C2 server at Contabo ur253.duckdns[.]org, which is used by Turla's infrastructure to deploy tools such as the clipboard monitor tool. This facilitates management and data transmission between infected devices and Turla's infrastructure.

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: domainName:"ur253.duckdns.org"

  • SHA-256: aba8b59281faa8c1c43a4ca7af075edd3e3516d3cef058a1f43b093177b8f83c
  • Sample: ANY.RUN

Wainscot

  • Secret Blizzard compromising Storm-0156

  • SHA-256: e298b83891b192b8a2782e638e7f5601acf13bab2f619215ac68a0b61230a273

  • Sample: ANY.RUN


Statuezy

  • Secret Blizzard compromising Storm-0156

Minipocket

  • Secret Blizzard compromising Storm-0156

IOC Summary

Pelmeni Wrapper: New Wrapper of Kazuar

IOCs (Click to expand)
  • SHA-256: 15f5e4808549ff67a79f84e23659da912ebbc1dc7c7b100c12b72384a27e412a
  • SHA-256: 7ae9768b79a6b75f814a1b7afaf841b1a4b7ba803b3d806823e81d24a84fd078
  • SHA-256: cccd6327dd5beee19cc3744b40f954c84ab016564b896c257f6871043a21cf0a
  • SHA-256: 6559d6cb2976334776ded3e7f8ce781c0e6fbaa69edbb0f16b902d06b5d8d8d9
  • SHA-256: 2164d54c415b48e906ad972a14d45c82af7cab814c6cf11729a994249690ed97
  • SHA-256: 564b2a3083e55933e4ce68b87c5e268c88d58f7ab41839e5a6e0c728a58e9cf2
  • SHA-256: 00256c7fd9a36c6a4805c467b15b3a72dbac2e6dbd12abe7d768f20ce6c8f09f
  • SHA-256: 1a3cc19345737bc76bcf61005ad6afeeea78540bddc627db052cede7a4c0d8e5
  • SHA-256: ebf10222bdd19bd8f14b7e94694c1534d4fe1d1047034aee7ffe9492cad4a92f
  • SHA-256: c91891c297971f46c470ea3b1934e5fb76f683776ba3edcdc1afe4f5398fc016
  • SHA-256: 9b97e740b65bc609210f095cd9407c990a9f71f580f001ea07300228c5256d62
  • SHA-256: 0e8cedf69e0708f77b8d8c7c9b96bf9386f0ec66c48b973bfa9718915ed260e9
  • URL: hxxps[:]//altavista.rs/wp-includes/ID3/PerceptionSimulation/
  • URL: hxxps[:]//m6front.sam-maintenance.com/wp-includes/customize/assembly/
  • URL: hxxps[:]//bibliotecaunicef.uy/catalog/notices/tags/
  • URL: wss[:]//127.0.0.1:20089/Test

Turla’s New Backdoor Targeting Polish NGOs

IOCs (Click to expand)
  • SHA-256: 267071df79927abd1e57f57106924dd8a68e1c4ed74e7b69403cdcdf6e6a453b
  • SHA-256: d6ac21a409f35a80ba9ccfe58ae1ae32883e44ecc724e4ae8289e7465ab2cf40
  • SHA-256: ad4d196b3d85d982343f32d52bffc6ebfeec7bf30553fa441fd7c3ae495075fc
  • SHA-256: 13c017cb706ef869c061078048e550dba1613c0f2e8f2e409d97a1c0d9949346
  • SHA-256: b376a3a6bae73840e70b2fa3df99d881def9250b42b6b8b0458d0445ddfbc044
  • domain: hanagram[.]jp
  • domain: thefinetreats[.]com
  • domain: caduff-sa[.]ch
  • domain: jeepcarlease[.]com
  • domain: buy-new-car[.]com
  • domain: carleasingguru[.]com
  • ip: 91[.]193.18.120

Secret Blizzard compromising Storm-0156

The Invisible Hand of Secret Blizzard

IOCs (Click to expand)
  • SHA-256: e298b83891b192b8a2782e638e7f5601acf13bab2f619215ac68a0b61230a273
  • SHA-256: 08803510089c8832df3f6db57aded7bfd2d91745e7dd44985d4c9cb9bd5fd1d2
  • SHA-256: aba8b59281faa8c1c43a4ca7af075edd3e3516d3cef058a1f43b093177b8f83c
  • SHA-256: 7c4ef30bd1b5cb690d2603e33264768e3b42752660c79979a5db80816dfb2ad2
  • SHA-256: dbbf8108fd14478ae05d3a3a6aabc242bff6af6eb1e93cbead4f5a23c3587ced
  • SHA-256: 7c7fad6b9ecb1e770693a6c62e0cc4183f602b892823f4a451799376be915912
  • SHA-256: e2d033b324450e1cb7575fedfc784e66488e342631f059988a9a2fd6e006d381
  • SHA-256: C039ec6622393f9324cacbf8cfaba3b7a41fe6929812ce3bd5d79b0fdedc884a
  • SHA-256: 59d7ec6ec97c6b958e00a3352d38dd13876fecdb2bb13a8541ab93248edde317
  • domain: connectotels[.]net
  • domain: hostelhotels[.]net
  • ip: 94.177.198[.]94
  • ip: 162.213.195[.]129
  • ip: 46.249.58[.]201
  • ip: 95.111.229[.]253
  • ip: 146.70.158[.]90
  • ip: 143.198.73[.]108
  • ip: 161.35.192[.]207
  • ip: 91.234.33[.]48
  • ip: 154.53.42[.]194
  • ip: 38.242.207[.]36
  • ip: 167.86.118[.]69
  • ip: 164.68.108[.]153
  • ip: 144.91.72[.]17
  • ip: 130.185.119[.]198
  • ip: 176.57.184[.]97
  • ip: 173.212.252[.]2
  • ip: 209.126.11[.]251
  • ip: 45.14.194[.]253
  • ip: 37.60.236[.]186
  • ip: 5.189.183[.]63
  • ip: 109.123.244[.]46
  • ip: 146.70.81[.]81
  • ip: 162.213.195[.]192
  • ip: 154.53.42[.]194
  • ip: 66.219.22[.]252
  • ip: 66.219.22[.]102
  • ip: 144.126.152[.]205
  • ip: 185.229.119[.]60
  • ip: 209.126.6[.]227
  • ip: 209.126.81[.]42
  • ip: 209.126.7[.]8
  • ip: 154.38.160[.]218
  • ip: 144.126.154[.]84
  • ip: 185.213.27[.]94
  • ip: 167.86.113[.]241
  • ip: 23.88.26[.]187
  • ip: 173.249.7[.]111
  • ip: 62.171.153[.]221
  • ip: 149.102.140[.]36
  • ip: 173.249.18[.]251
  • ip: 84.247.181[.]64
  • ip: 38.242.219[.]13
  • ip: 62.171.153[.]221
  • ip: 38.242.211[.]87
  • ip: 45.14.194[.]253
  • ip: 173.212.206[.]227
  • ip: 209.145.52[.]172

Turla: A Master’s Art of Evasion

IOCs (Click to expand)
  • SHA-256: cac4d4364d20fa343bf681f6544b31995a57d8f69ee606c4675db60be5ae8775
  • SHA-256: c2618fb013135485f9f9aa27983df3371dfdcb7beecde86d02cee0c258d5ed7f
  • SHA-256: b6abbeab6e000036c6cdffc57c096d796397263e280ea264eba73ac5bab39441
  • SHA-256: 7091ce97fb5906680c1b09558bafdf9681a81f5f524677b90fd0f7fc0a05bc00
  • URL: hxxps://ies.inquirer.com.ph/advprod03/assets/images/Advisory23-UCDMS04-11-01.zip
  • domain: files.philbendeck.com

Cyble report. Tiny backdoor

IOCs (Click to expand)
  • SHA-256: b4db8e598741193ea9e04c2111d0c15ba79b2fa098efc3680a63ef457e60dbd9
  • SHA-256: 6829ab9c4c8a9a0212740f46bf93b1cbe5d4256fb4ff66d65a3a6eb6c55758a1
  • SHA-256: 8c97df4ca1a5995e22c2c4887bea2945269d6f5f158def98d5ebdd5311bb20c4
  • SHA-256: 76629afb86bd9024c3ea6759eeea197ba6c8c780e0041d1f8182d206cf3bd1b4

TURLA’s campaign in Eastern Europe

IOCs (Click to expand)
  • ip: 45.153.241[.]162
  • ip: 79.110.52[.]218
  • ip: 149.154.157[.]11
  • domain: baltdefcol.webredirect[.]org
  • domain: wkoinfo.webredirect[.]org
  • domain: jadlactnato.webredirect[.]org
  • MD5: f6e755e2af0231a614975d64ea3c8116
  • MD5: f223e046dd4e3f98bfeb1263a78ff080

YARA Rules

Turla Technical Analysis Report


rule TinyTurlaNG {
    meta:
        date = "18.04.2024"
        author = "Bilal BAKARTEPE"
        hash = "0f2e9f501ca9780eff309b7022c9b01a"

    strings:
        $pwshll_command_1 = "Set-PSReadLineOption -HistorySaveStyle SaveNothing"
        $pwshll_command_2 = "chcp 437 > $null"
        $c2_command_1 = "timeout"
        $c2_command_2 = "killme"
        $c2_command_3 = "changeshell"
        $c2_command_4 = "changepoint"
        $c2_command_5 = "get"
        $c2_command_6 = "post"

    condition:
        all of them
}

TinyTurla - Turla deploys new malware


import "pe"

rule TinyTurla {
    meta:
        author = "Cisco Talos"
        description = "Detects Tiny Turla backdoor DLL"

    strings:
        $a = "Title:" fullword wide
        $b = "Hosts" fullword wide
        $c = "Security" fullword wide
        $d = "TimeLong" fullword wide
        $e = "TimeShort" fullword wide
        $f = "MachineGuid" fullword wide
        $g = "POST" fullword wide
        $h = "WinHttpSetOption" fullword ascii
        $i = "WinHttpQueryDataAvailable" fullword ascii

    condition:
        pe.is_pe and
        pe.characteristics & pe.DLL and
        pe.exports("ServiceMain") and
        all of them
}

Cyble report. Tiny backdoor


rule Tiny_Backdoor {
    
    meta:
        author = "Cyble Research and Intelligence Labs"
        description = "Detects Malicious MSBuild Project file used in this campaign"
        date = "2024-05-20"
        os = "Windows"
    
    strings:
        $a1 = "[<shell>]" ascii wide
        $a2 = "[<sleep>]" ascii wide
        $a3 = "[<upload>]" ascii wide
        $a4 = "[<download>]" ascii wide
        $a5 = "?m=c&id=" ascii wide fullword
    
    condition:
        all of them
}

Sigma Rules:

Turla Technical Analysis Report


title: C2 Communication for TinyTurla-NG
description: Detects communication with the command and control server
author: Bilal Bakartepe
date: 2024/04/18
status: experimental
logsource:
  product: windows
  category: network_connection
detection:
  selectionURL:
    cs-uri|contains:
      - "https://jeepcarlease.com/wp-includes/blocks/rss.old.php"
      - "https://caduff-sa.ch/wp-includes/blocks/rss.old.php"
      - "hanagram.jp"
      - "buy-new-car.com"
      - "thefinetreats.com"
      - "carleasingguru.com"
  condition: selectionURL
falsepositives:
  - Unknown
level: high

References

  • https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/
  • https://lab52.io/blog/pelmeni-wrapper-new-wrapper-of-kazuar-turla-backdoor/?ref=news.risky.biz
  • https://blog.talosintelligence.com/tinyturla-next-generation/
  • https://blog.talosintelligence.com/tinyturla-ng-tooling-and-c2/
  • https://blog.talosintelligence.com/tinyturla-full-kill-chain/
  • https://github.com/echocti/ECHO-Reports/blob/main/APT%20Reports/Turla/Turla%20Technical%20Analysis%20Report.pdf
  • https://www.microsoft.com/en-us/security/blog/2024/12/04/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/
  • https://blog.lumen.com/snowblind-the-invisible-hand-of-secret-blizzard/
  • https://thehackernews.com/2024/12/russia-linked-turla-exploits-pakistani.html
  • https://gbhackers.com/turla-aptc-new-tool/
  • https://cybersecuritynews.com/turla-apt-group-attacking/
  • https://www.gdatasoftware.com/blog/2024/07/37977-turla-evasion-lnk-files
  • https://intel471.com/blog/threat-hunting-case-study-uncovering-turla
  • https://nikhilh-20.github.io/blog/turla_backdoor_defenses_bypass/
  • https://gbhackers.com/turla-hackers-lnk-fileless-malware/
  • https://cyble.com/blog/tiny-backdoor-goes-undetected-suspected-turla-leveraging-msbuild-to-evade-detection/
  • https://gbhackers.com/turla-hackers-microsoft-build-malware/
  • https://blog.sekoia.io/turla-new-phishing-campaign-eastern-europe/