#turla — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #turla, aggregated by home.social.
-
EU, UK sanction Russian cyberespionage networks over destructive attacks
European governments sanctioned Russian individuals and organizations Monday over what they said was a years-long campaign of cyberespionage…
#Europe #EU #Austria #cyberespionage #Cyprus #Energy #EuropeanUnion #Finland #fsb #Germany #gru #lummastealer #Netherlands #Poland #Romania #Russia #secretblizzard #Slovakia #turla #unitedkingdom(u.k.)
https://www.europesays.com/europe/93170/ -
EU, UK sanction Russian cyberespionage networks over destructive attacks
European governments sanctioned Russian individuals and organizations Monday over what they said was a years-long campaign of cyberespionage…
#EuropeSays #Russia #Austria #cyberespionage #Cyprus #Energy #EuropeanUnion #Finland #FSB #Germany #gru #lummastealer #Netherlands #Poland #Romania #secretblizzard #Slovakia #turla #unitedkingdom(u.k.)
https://www.europesays.com/russia/39406/ -
EU, UK sanction Russian cyberespionage networks over destructive attacks https://www.byteseu.com/2192247/ #Austria #cyberespionage #Cyprus #Energy #EuropeanUnion #Finland #FSB #Germany #GreatBritain #GRU #LummaStealer #Netherlands #Poland #Romania #Russia #SecretBlizzard #Slovakia #turla #UnitedKingdom #UnitedKingdom(uK)
-
EU sanktioniert Russland wegen schwerer Cyberangriffe und Sabotage
EU sanktioniert Russland wegen schwerer Cyberangriffe und Sabotage Der Europäische Rat hat am Montag eine scharfe Rüge gegen…
#EuropeSays #EU #Europa #Cybercrime #EuropäischeUnion #FSB #GRU #Hacktivismus #Industriespionage #Iran #IT #Netzpolitik #NotPetya #Russland #Security #Turla #Ukraine-Krieg
https://www.europesays.com/europa/67583/ -
https://www.europesays.com/hu/171390/ Az orosz állambiztonság titkos hackercsoportját szankcionálja az Európai Unió, Berlinben és Párizsban is bekérették az orosz nagykövetet #EurópaiUnió #franciaország #FSZB #Hungarian #kibertámadás #Külföld #Magyar #németország #News #OroszKiberkémkedés #oroszország #szankciók #Turla #Világ #World #WorldNews
-
Turla STOCKSTAY backdoor attacks Ukrainian military targets. Russian cyber espionage groups deploy this .NET malware via malicious RDP and WinRAR flaws.
#Turla #STOCKSTAY #CyberEspionage #Malware
https://securityonline.info/turla-stockstay-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
Turla STOCKSTAY backdoor attacks Ukrainian military targets. Russian cyber espionage groups deploy this .NET malware via malicious RDP and WinRAR flaws.
#Turla #STOCKSTAY #CyberEspionage #Malware
https://securityonline.info/turla-stockstay-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Pulse ID: 6a42011da908e84ee3e960e6
Pulse Link: https://otx.alienvault.com/pulse/6a42011da908e84ee3e960e6
Pulse Author: Tr1sa111
Created: 2026-06-29 05:22:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Turla #bot #Tr1sa111
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Pulse ID: 6a42011da908e84ee3e960e6
Pulse Link: https://otx.alienvault.com/pulse/6a42011da908e84ee3e960e6
Pulse Author: Tr1sa111
Created: 2026-06-29 05:22:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Turla #bot #Tr1sa111
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Pulse ID: 6a42011da908e84ee3e960e6
Pulse Link: https://otx.alienvault.com/pulse/6a42011da908e84ee3e960e6
Pulse Author: Tr1sa111
Created: 2026-06-29 05:22:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Turla #bot #Tr1sa111
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Pulse ID: 6a42011da908e84ee3e960e6
Pulse Link: https://otx.alienvault.com/pulse/6a42011da908e84ee3e960e6
Pulse Author: Tr1sa111
Created: 2026-06-29 05:22:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Turla #bot #Tr1sa111
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Pulse ID: 6a42011da908e84ee3e960e6
Pulse Link: https://otx.alienvault.com/pulse/6a42011da908e84ee3e960e6
Pulse Author: Tr1sa111
Created: 2026-06-29 05:22:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Turla #bot #Tr1sa111
-
📰 Russian APT Turla Unleashes New 'STOCKSTAY' Backdoor in Ukraine Espionage Attacks
🇷🇺 Russia's Turla APT deploys new 'STOCKSTAY' .NET backdoor in espionage attacks on Ukraine. Google reports the malware shares code with the Kazuar implant and uses WebSockets for C2. 🕵️♂️ #ThreatIntel #Malware #Turla #CyberSecurity #Ukraine
🌐 cyber[.]netsecops[.]io
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
#Turla #STOCKSTAY
https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/ -
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
#Turla #STOCKSTAY
https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/ -
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
#Turla #STOCKSTAY
https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/ -
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
#Turla #STOCKSTAY
https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/ -
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
#Turla #STOCKSTAY
https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/ -
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Threat Intelligence Group has identified STOCKSTAY, a .NET backdoor continuously developed and deployed by Russia-linked Turla (FSB Center 16) since December 2022. The multi-component malware communicates via secure WebSocket connections and targets government and military organizations in Ukraine, as well as entities interested in Italian foreign policy. STOCKSTAY shares significant code overlaps with KAZUAR, particularly the K1MORPHER obfuscation mechanism. The threat actor employs academic and diplomatic lures, malicious RDP files, and compromised Ukrainian infrastructure for deployment. STOCKSTAY demonstrates environmental keying for configuration protection and operates at multiple operational stages. The malware's modular architecture separates C2 communication, task orchestration, and execution into distinct components, mirroring KAZUAR's design philosophy and indicating shared development resources within Turla's cyber espionage arsenal.
Pulse ID: 6a3db99d3f27ba984f5154ff
Pulse Link: https://otx.alienvault.com/pulse/6a3db99d3f27ba984f5154ff
Pulse Author: AlienVault
Created: 2026-06-25 23:28:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Espionage #Google #Government #InfoSec #Italian #Kazuar #Malware #Military #NET #OTX #OpenThreatExchange #RAT #RCE #RDP #Russia #Turla #UK #Ukr #Ukraine #Ukrainian #bot #AlienVault
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Threat Intelligence Group has identified STOCKSTAY, a .NET backdoor continuously developed and deployed by Russia-linked Turla (FSB Center 16) since December 2022. The multi-component malware communicates via secure WebSocket connections and targets government and military organizations in Ukraine, as well as entities interested in Italian foreign policy. STOCKSTAY shares significant code overlaps with KAZUAR, particularly the K1MORPHER obfuscation mechanism. The threat actor employs academic and diplomatic lures, malicious RDP files, and compromised Ukrainian infrastructure for deployment. STOCKSTAY demonstrates environmental keying for configuration protection and operates at multiple operational stages. The malware's modular architecture separates C2 communication, task orchestration, and execution into distinct components, mirroring KAZUAR's design philosophy and indicating shared development resources within Turla's cyber espionage arsenal.
Pulse ID: 6a3db99d3f27ba984f5154ff
Pulse Link: https://otx.alienvault.com/pulse/6a3db99d3f27ba984f5154ff
Pulse Author: AlienVault
Created: 2026-06-25 23:28:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Espionage #Google #Government #InfoSec #Italian #Kazuar #Malware #Military #NET #OTX #OpenThreatExchange #RAT #RCE #RDP #Russia #Turla #UK #Ukr #Ukraine #Ukrainian #bot #AlienVault
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Threat Intelligence Group has identified STOCKSTAY, a .NET backdoor continuously developed and deployed by Russia-linked Turla (FSB Center 16) since December 2022. The multi-component malware communicates via secure WebSocket connections and targets government and military organizations in Ukraine, as well as entities interested in Italian foreign policy. STOCKSTAY shares significant code overlaps with KAZUAR, particularly the K1MORPHER obfuscation mechanism. The threat actor employs academic and diplomatic lures, malicious RDP files, and compromised Ukrainian infrastructure for deployment. STOCKSTAY demonstrates environmental keying for configuration protection and operates at multiple operational stages. The malware's modular architecture separates C2 communication, task orchestration, and execution into distinct components, mirroring KAZUAR's design philosophy and indicating shared development resources within Turla's cyber espionage arsenal.
Pulse ID: 6a3db99d3f27ba984f5154ff
Pulse Link: https://otx.alienvault.com/pulse/6a3db99d3f27ba984f5154ff
Pulse Author: AlienVault
Created: 2026-06-25 23:28:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Espionage #Google #Government #InfoSec #Italian #Kazuar #Malware #Military #NET #OTX #OpenThreatExchange #RAT #RCE #RDP #Russia #Turla #UK #Ukr #Ukraine #Ukrainian #bot #AlienVault
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Threat Intelligence Group has identified STOCKSTAY, a .NET backdoor continuously developed and deployed by Russia-linked Turla (FSB Center 16) since December 2022. The multi-component malware communicates via secure WebSocket connections and targets government and military organizations in Ukraine, as well as entities interested in Italian foreign policy. STOCKSTAY shares significant code overlaps with KAZUAR, particularly the K1MORPHER obfuscation mechanism. The threat actor employs academic and diplomatic lures, malicious RDP files, and compromised Ukrainian infrastructure for deployment. STOCKSTAY demonstrates environmental keying for configuration protection and operates at multiple operational stages. The malware's modular architecture separates C2 communication, task orchestration, and execution into distinct components, mirroring KAZUAR's design philosophy and indicating shared development resources within Turla's cyber espionage arsenal.
Pulse ID: 6a3db99d3f27ba984f5154ff
Pulse Link: https://otx.alienvault.com/pulse/6a3db99d3f27ba984f5154ff
Pulse Author: AlienVault
Created: 2026-06-25 23:28:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Espionage #Google #Government #InfoSec #Italian #Kazuar #Malware #Military #NET #OTX #OpenThreatExchange #RAT #RCE #RDP #Russia #Turla #UK #Ukr #Ukraine #Ukrainian #bot #AlienVault
-
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Threat Intelligence Group has identified STOCKSTAY, a .NET backdoor continuously developed and deployed by Russia-linked Turla (FSB Center 16) since December 2022. The multi-component malware communicates via secure WebSocket connections and targets government and military organizations in Ukraine, as well as entities interested in Italian foreign policy. STOCKSTAY shares significant code overlaps with KAZUAR, particularly the K1MORPHER obfuscation mechanism. The threat actor employs academic and diplomatic lures, malicious RDP files, and compromised Ukrainian infrastructure for deployment. STOCKSTAY demonstrates environmental keying for configuration protection and operates at multiple operational stages. The malware's modular architecture separates C2 communication, task orchestration, and execution into distinct components, mirroring KAZUAR's design philosophy and indicating shared development resources within Turla's cyber espionage arsenal.
Pulse ID: 6a3db99d3f27ba984f5154ff
Pulse Link: https://otx.alienvault.com/pulse/6a3db99d3f27ba984f5154ff
Pulse Author: AlienVault
Created: 2026-06-25 23:28:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Espionage #Google #Government #InfoSec #Italian #Kazuar #Malware #Military #NET #OTX #OpenThreatExchange #RAT #RCE #RDP #Russia #Turla #UK #Ukr #Ukraine #Ukrainian #bot #AlienVault
-
📰 Russian APT Turla Evolves Kazuar Backdoor into Stealthy P2P Botnet
🇷🇺 Russian APT Turla has upgraded its Kazuar backdoor into a modular P2P botnet. The new architecture enhances stealth and resilience, making it harder to detect and disrupt. The focus remains on long-term espionage. #Turla #APT #Kazuar #CyberSecur...
🌐 cyber[.]netsecops[.]io
-
Kazuar si evolve: Secret Blizzard (Turla) trasforma il suo backdoor storico in una botnet P2P modulare invisibile
Il gruppo russo Secret Blizzard (Turla/FSB) ha trasformato il malware Kazuar in una botnet peer-to-peer con tre moduli distinti (Kernel, Bridge, Worker) e 150 parametri di configurazione. La nuova architettura usa un sistema di elezione del leader per ridurre al minimo il traffico verso i server C2, rendendo il rilevamento estremamente difficile. Obiettivi: governi, ambasciate e settore difesa in Europa e Ucraina. -
Kazuar si evolve: Secret Blizzard (Turla) trasforma il suo backdoor storico in una botnet P2P modulare invisibile
Il gruppo russo Secret Blizzard (Turla/FSB) ha trasformato il malware Kazuar in una botnet peer-to-peer con tre moduli distinti (Kernel, Bridge, Worker) e 150 parametri di configurazione. La nuova architettura usa un sistema di elezione del leader per ridurre al minimo il traffico verso i server C2, rendendo il rilevamento estremamente difficile. Obiettivi: governi, ambasciate e settore difesa in Europa e Ucraina. -
Kazuar si evolve: Secret Blizzard (Turla) trasforma il suo backdoor storico in una botnet P2P modulare invisibile
Il gruppo russo Secret Blizzard (Turla/FSB) ha trasformato il malware Kazuar in una botnet peer-to-peer con tre moduli distinti (Kernel, Bridge, Worker) e 150 parametri di configurazione. La nuova architettura usa un sistema di elezione del leader per ridurre al minimo il traffico verso i server C2, rendendo il rilevamento estremamente difficile. Obiettivi: governi, ambasciate e settore difesa in Europa e Ucraina. -
Kazuar si evolve: Secret Blizzard (Turla) trasforma il suo backdoor storico in una botnet P2P modulare invisibile
Il gruppo russo Secret Blizzard (Turla/FSB) ha trasformato il malware Kazuar in una botnet peer-to-peer con tre moduli distinti (Kernel, Bridge, Worker) e 150 parametri di configurazione. La nuova architettura usa un sistema di elezione del leader per ridurre al minimo il traffico verso i server C2, rendendo il rilevamento estremamente difficile. Obiettivi: governi, ambasciate e settore difesa in Europa e Ucraina. -
Kazuar si evolve: Secret Blizzard (Turla) trasforma il suo backdoor storico in una botnet P2P modulare invisibile
Il gruppo russo Secret Blizzard (Turla/FSB) ha trasformato il malware Kazuar in una botnet peer-to-peer con tre moduli distinti (Kernel, Bridge, Worker) e 150 parametri di configurazione. La nuova architettura usa un sistema di elezione del leader per ridurre al minimo il traffico verso i server C2, rendendo il rilevamento estremamente difficile. Obiettivi: governi, ambasciate e settore difesa in Europa e Ucraina. -
Russian Hackers Upgrade Kazuar Backdoor to Modular Botnet
Microsoft researchers have uncovered a significant upgrade to the Kazuar backdoor, transforming it into a modular peer-to-peer botnet by the notorious Russian hacker group, Secret Blizzard. This sophisticated tool has been used to target high-stakes organizations and critical systems across Europe, Asia, and Ukraine.
#RussianHackers #KazuarBackdoor #ModularBotnet #SecretBlizzard #Turla
-
Turla Upgrades Kazuar Backdoor to Modular P2P Botnet
Microsoft's Threat Intelligence team has uncovered a significant upgrade to the Kazuar backdoor by the notorious Russian state-sponsored group Turla, now a modular P2P botnet designed for long-term intelligence collection. This move enables Turla to maintain a persistent grip on compromised systems.
-
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
#CVE_2025_8088 #RomComGroup #APT44 #TEMP.Armageddon #Gamaredon #Turla #zeroplayer
https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability -
COMmand & Evade: Turla's Kazuar v3 Loader
#Turla #KazuarV3Loader
https://r136a1.dev/2026/01/14/command-and-evade-turlas-kazuar-v3-loader/ -
COMmand & Evade: Turla's Kazuar v3 Loader
#Turla #KazuarV3Loader
https://r136a1.dev/2026/01/14/command-and-evade-turlas-kazuar-v3-loader/ -
COMmand & Evade: Turla's Kazuar v3 Loader
#Turla #KazuarV3Loader
https://r136a1.dev/2026/01/14/command-and-evade-turlas-kazuar-v3-loader/ -
COMmand & Evade: Turla's Kazuar v3 Loader
#Turla #KazuarV3Loader
https://r136a1.dev/2026/01/14/command-and-evade-turlas-kazuar-v3-loader/ -
COMmand & Evade: Turla's Kazuar v3 Loader
#Turla #KazuarV3Loader
https://r136a1.dev/2026/01/14/command-and-evade-turlas-kazuar-v3-loader/ -
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Two of the Kremlin’s most active hack groups are collaborating, ESET says - Two of the Kremlin’s most active hacking units recently were... - https://arstechnica.com/security/2025/09/two-of-the-kremlins-most-active-hack-groups-are-collaborating-eset-says/ #advancedpersistentthreat #gamaredon #security #biz #russia #turla #apt
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla
-
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions https://www.securityweek.com/turla-and-gamaredon-working-together-in-fresh-ukrainian-intrusions/ #Malware&Threats #Gamaredon #malware #Ukraine #Russia #Turla