Turla
Also reported as Secret Blizzard, Group 88, Waterbug, Snake, Blue Python and 38 other names. Linked to Russia by four sources.
Reports per quarter
Techniques seen in the last two years
- T1041 3 reports reports only
- T1057 3 reports in ATT&CK
- T1071.001 3 reports in ATT&CK
- T1082 3 reports in ATT&CK
- T1083 3 reports in ATT&CK
- T1102 3 reports in ATT&CK
- T1135 3 reports reports only
- T1012 2 reports in ATT&CK
- T1025 2 reports in ATT&CK
- T1036.005 2 reports in ATT&CK
Show all 104 techniques Show fewer
- T1053.005 2 reports reports only
- T1059 2 reports reports only
- T1059.001 2 reports in ATT&CK
- T1071 2 reports reports only
- T1074.001 2 reports reports only
- T1091 2 reports reports only
- T1112 2 reports in ATT&CK
- T1119 2 reports reports only
- T1120 2 reports in ATT&CK
- T1189 2 reports in ATT&CK
- T1204.002 2 reports reports only
- T1543.003 2 reports reports only
- T1567.002 2 reports in ATT&CK
- T1583.004 2 reports reports only
- T1590.005 2 reports reports only
- T1592.002 2 reports reports only
- T1598.003 2 reports reports only
- T1001 1 report reports only
- T1005 1 report in ATT&CK
- T1008 1 report reports only
- T1010 1 report reports only
- T1016 1 report in ATT&CK
- T1016.001 1 report in ATT&CK
- T1018 1 report in ATT&CK
- T1020 1 report reports only
- T1021 1 report reports only
- T1027 1 report reports only
- T1027.013 1 report reports only
- T1033 1 report reports only
- T1036.004 1 report reports only
- T1036.008 1 report reports only
- T1046 1 report reports only
- T1047 1 report reports only
- T1048 1 report reports only
- T1048.002 1 report reports only
- T1052.001 1 report reports only
- T1053 1 report reports only
- T1055 1 report in ATT&CK
- T1059.003 1 report in ATT&CK
- T1059.006 1 report in ATT&CK
- T1069 1 report reports only
- T1070.004 1 report reports only
- T1078.003 1 report in ATT&CK
- T1087 1 report reports only
- T1087.001 1 report in ATT&CK
- T1090 1 report in ATT&CK
- T1090.001 1 report in ATT&CK
- T1092 1 report reports only
- T1102.002 1 report in ATT&CK
- T1105 1 report in ATT&CK
- T1106 1 report in ATT&CK
- T1114.001 1 report reports only
- T1132.001 1 report reports only
- T1140 1 report in ATT&CK
- T1190 1 report reports only
- T1195 1 report reports only
- T1204 1 report reports only
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1480.001 1 report reports only
- T1518 1 report reports only
- T1543 1 report reports only
- T1546 1 report reports only
- T1547.001 1 report in ATT&CK
- T1547.009 1 report reports only
- T1552.001 1 report reports only
- T1552.004 1 report reports only
- T1557 1 report reports only
- T1560.002 1 report reports only
- T1564.001 1 report reports only
- T1566 1 report reports only
- T1566.001 1 report reports only
- T1566.002 1 report in ATT&CK
- T1566.003 1 report reports only
- T1567 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1571 1 report reports only
- T1572 1 report reports only
- T1573 1 report reports only
- T1573.001 1 report reports only
- T1573.002 1 report reports only
- T1574.001 1 report reports only
- T1583.001 1 report reports only
- T1583.003 1 report reports only
- T1583.007 1 report reports only
- T1584.003 1 report in ATT&CK
- T1584.006 1 report in ATT&CK
- T1585.003 1 report reports only
- T1587.001 1 report in ATT&CK
- T1588.002 1 report in ATT&CK
- T1608 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-1999-0314
- CVE-2007-5633
- CVE-2008-3431 KEV
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-1125
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-1592
- CVE-2010-3333 KEV
Show all 267 CVEs Show fewer
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3402 KEV
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-3918 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-5947
- CVE-2013-7331 KEV
- CVE-2013-7389
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0057
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-2051 KEV
- CVE-2015-2360 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0040 KEV
- CVE-2016-0147
- CVE-2016-0165 KEV
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0001 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11292 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-17215
- CVE-2017-5638 KEV ransomware
- CVE-2017-6190
- CVE-2017-7269 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-15454
- CVE-2018-1579
- CVE-2018-15961 KEV
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4876
- CVE-2018-4878 KEV ransomware
- CVE-2018-5002 KEV
- CVE-2018-6055
- CVE-2018-7445 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-8641
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1069 KEV ransomware
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-15126
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0968 KEV ransomware
- CVE-2020-10148 KEV
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-35730 KEV
- CVE-2020-3702
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-25323
- CVE-2021-25324
- CVE-2021-25325
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30657 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-33766 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-28252 KEV ransomware
- CVE-2023-34362 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-9680 KEV ransomware
- CVE-2025-10035 KEV ransomware
- CVE-2025-8088 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East
-
Turla/Belugasturgeon Compromises Government | Accenture
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Turla/Belugasturgeon Compromises Government | Accenture
-
Transparent Tribe, APT 36 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Transparent Tribe, APT 36 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Amadey (Malware Family)
Show all 408 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Crimson RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor EternalPetya (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Meterpreter (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TwoFace (Malware Family)
-
Turla, Waterbug, Venomous Bear - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Turla, Waterbug, Venomous Bear - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Andromeda (Malware Family)
-
Meet the GoldenJackal APT group. Don’t expect any howls
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet the GoldenJackal APT group. Don’t expect any howls
-
Hunting Russian Intelligence “Snake” Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting Russian Intelligence “Snake” Malware
-
Tomiris called, they want their Turla malware back
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tomiris called, they want their Turla malware back
-
Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
-
Turla- A Galaxy of Opportunity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla- A Galaxy of Opportunity
-
Reassessing cyberwarfare. Lessons learned in 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reassessing cyberwarfare. Lessons learned in 2022
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-Report
-
Malware development- persistence - part 11. Powershell profile. Simple Cplusplus example.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware development- persistence - part 11. Powershell profile. Simple Cplusplus example.
-
Space Invaders- Cyber Threats That Are Out Of This World
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Invaders- Cyber Threats That Are Out Of This World
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
-
Continued cyber activity in Eastern Europe observed by TAG
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Continued cyber activity in Eastern Europe observed by TAG
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
Update on cyber activity in Eastern Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Update on cyber activity in Eastern Europe
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
Complete dissection of an APK with a suspicious C2 Server
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Complete dissection of an APK with a suspicious C2 Server
-
Newly found Android malware records audio, tracks your location
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Newly found Android malware records audio, tracks your location
-
A Step-by-Step Analysis of the Russian APT Turla Backdoor called TinyTurla
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Step-by-Step Analysis of the Russian APT Turla Backdoor called TinyTurla
-
Looking for Penquins in the Wild
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Looking for Penquins in the Wild
-
Full Spectrum Detections for 5 Popular Web Shells- Alfa, SharPyShell, Krypton, ASPXSpy, and TWOFACE
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Full Spectrum Detections for 5 Popular Web Shells- Alfa, SharPyShell, Krypton, ASPXSpy, and TWOFACE
-
The BigBoss Rules- Something about one of the Uroburos’ RPC-based backdoors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The BigBoss Rules- Something about one of the Uroburos’ RPC-based backdoors
-
Operation GhostShell_ Novel RAT Targets Global Aerospace and Telecoms Firms
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation GhostShell_ Novel RAT Targets Global Aerospace and Telecoms Firms
-
Deobfuscating PowerShell Malware Droppers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deobfuscating PowerShell Malware Droppers
-
TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12021
-
New Version of Kido (Conficker) (Kaspersky Lab)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Version of Kido (Conficker) (Kaspersky Lab)
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
Nice to meet you too My name is Ryuk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nice to meet you too My name is Ryuk
-
IronNetInjector- Turla’s New Malware Loading Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IronNetInjector- Turla’s New Malware Loading Tool
-
Mimecast links security breach to SolarWinds hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mimecast links security breach to SolarWinds hackers
-
On attribution- APT28, APT29…Turla- No, they are NOT the same
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor On attribution- APT28, APT29…Turla- No, they are NOT the same
-
The Devil’s in the Details- SUNBURST Attribution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Devil’s in the Details- SUNBURST Attribution
-
Sunburst backdoor – code overlaps with Kazuar
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sunburst backdoor – code overlaps with Kazuar
-
securelist.com-Sunburst backdoor code overlaps with Kazuar
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor securelist.com-Sunburst backdoor code overlaps with Kazuar
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
Turla Crutch_ Keeping the “back door” open _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Turla Crutch_ Keeping the “back door” open _ WeLiveSecurity
-
Turla Crutch- Keeping the “back door” open
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla Crutch- Keeping the “back door” open
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Enigmatic Energetic Bear
-
Malware Analysis Report (AR20-303A)- PowerShell Script- ComRAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis Report (AR20-303A)- PowerShell Script- ComRAT
-
Turla uses HyperStack, Carbon, and Kazuar to compromise government entity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla uses HyperStack, Carbon, and Kazuar to compromise government entity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla Carbon System
-
An overview of targeted attacks and APTs on Linux
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An overview of targeted attacks and APTs on Linux
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution- A Puzzle
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Turla _ Venomous Bear updates its arsenal_ _NewPass_ appears on the APT threat scene - Telsy
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Turla _ Venomous Bear updates its arsenal_ _NewPass_ appears on the APT threat scene - Telsy
-
Turla - Venomous Bear updates its arsenal- “NewPass” appears on the APT threat scene
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla - Venomous Bear updates its arsenal- “NewPass” appears on the APT threat scene
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
EKANS Ransomware Misconceptions and Misunderstandings
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor EKANS Ransomware Misconceptions and Misunderstandings
-
AcidBox- Rare Malware Repurposing Turla Group Exploit Targeted Russian Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AcidBox- Rare Malware Repurposing Turla Group Exploit Targeted Russian Organizations
-
AcidBox_ Rare Malware Repurposing Turla Group Exploit Targeted Russian Organizations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor AcidBox_ Rare Malware Repurposing Turla Group Exploit Targeted Russian Organizations
-
Looking at Big Threats Using Code Similarity. Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Looking at Big Threats Using Code Similarity. Part 1
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SysInTURLA
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Turla_ComRAT
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ACIDBOX Clustering
-
From Agent.BTZ to ComRAT v4- A ten‑year journey
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Agent.BTZ to ComRAT v4- A ten‑year journey
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
COMpfun authors spoof visa application with HTTP status-based Trojan _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor COMpfun authors spoof visa application with HTTP status-based Trojan _ Securelist
-
COMpfun authors spoof visa application with HTTP status-based Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COMpfun authors spoof visa application with HTTP status-based Trojan
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q12020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report-bb-decade-of-the-rats
-
Tracking Turla_ New backdoor delivered via Armenian watering holes _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking Turla_ New backdoor delivered via Armenian watering holes _ WeLiveSecurity
-
Tracking Turla- New backdoor delivered via Armenian watering holes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking Turla- New backdoor delivered via Armenian watering holes
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
EKANS Ransomware and ICS Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor EKANS Ransomware and ICS Operations
-
IBM X-Force IRIS ZeroCleare - Tehcnical Paper
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor IBM X-Force IRIS ZeroCleare - Tehcnical Paper
-
Dustman APT- Art of Copy-Paste
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dustman APT- Art of Copy-Paste
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Saudi-Arabia-CNA-report
-
Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Microsoft Word - New Destructive Wiper ZeroCleare v1 MLM comments.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - New Destructive Wiper ZeroCleare v1 MLM comments.docx
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
Advisory- Turla group exploits Iranian APT to expand coverage of victims
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advisory- Turla group exploits Iranian APT to expand coverage of victims
-
COMpfun successor Reductor infects files on the fly to compromise TLS traffic
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COMpfun successor Reductor infects files on the fly to compromise TLS traffic
-
Mapping the connections inside Russia APT Ecosystem
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mapping the connections inside Russia APT Ecosystem
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT34- The Helix Kitten Cybercriminal Group Loves to Meow Middle Eastern and International Organizations
-
An Overview of Public Platform C2’s
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Overview of Public Platform C2’s
-
APT_trends_report_Q2_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2019_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2019
-
Turla Indicators of Compromise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla Indicators of Compromise
-
Analyzing KSL0T Turlas Keylogger Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing KSL0T Turlas Keylogger Part 1
-
Analyzing KSL0T Turlas Keylogger Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing KSL0T Turlas Keylogger Part 2
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Waterbug_ Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Waterbug_ Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
-
Waterbug- Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Waterbug- Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
-
Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Possible Turla HTTP Listener
-
Zebrocy Multilanguage Malware Salad
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy Multilanguage Malware Salad
-
A dive into Turla PowerShell usage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A dive into Turla PowerShell usage
-
A dive into Turla PowerShell usage
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A dive into Turla PowerShell usage
-
Turla LightNeuron- An email too far
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla LightNeuron- An email too far
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET-LightNeuron
-
TDL (Turla Driver Loader) Repository
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TDL (Turla Driver Loader) Repository
-
Decoded Turla Powershell Implant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Decoded Turla Powershell Implant
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q2 2017
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
Fallout Exploit Kit Releases the Kraken Ransomware on Its Victims
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fallout Exploit Kit Releases the Kraken Ransomware on Its Victims
-
Shedding Skin – Turla’s Fresh Faces
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shedding Skin – Turla’s Fresh Faces
-
Turla Outlook Backdoor Uses Clever Tactics for Stealth and Persistence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla Outlook Backdoor Uses Clever Tactics for Stealth and Persistence
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Eset-Turla-Outlook-Backdoor
-
Mosquito campaign by Turla undergoes significant TTPs shift
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mosquito campaign by Turla undergoes significant TTPs shift
-
Turla Mosquito- A shift towards more generic tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla Mosquito- A shift towards more generic tools
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q1 2018
-
Masha and these Bears - 2018 Sofacy Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Masha and these Bears - 2018 Sofacy Activity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor masha-and-these-bears
-
ukatemicrysys_territorialdispute
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ukatemicrysys_territorialdispute
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Turla_APT
-
OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN
-
This hacking gang just updated the malware it uses against UK targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor This hacking gang just updated the malware it uses against UK targets
-
Turla group update Neuron malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Turla group update Neuron malware
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla group malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Turla_Mosquito
-
Turla group using Neuron and Nautilus tools alongside Snake malware
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Turla group using Neuron and Nautilus tools alongside Snake malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society | Volexity
-
Introducing WhiteBear - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing WhiteBear - Securelist
-
Analysis of a malicious DOC used by Turla APT group; hunting persistence via PowerShell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of a malicious DOC used by Turla APT group; hunting persistence via PowerShell
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Variants of Agent.BTZ-ComRAT Found- The Threat That Hit The Pentagon In 2008 Still Evolving; Part 2-2
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Introducing WhiteBear
-
New ESET research uncovers Gazer, the stealthy backdoor that spies on embassies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New ESET research uncovers Gazer, the stealthy backdoor that spies on embassies
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing WhiteBear
-
Cyberespionage Group Turla Deploys Backdoor Ahead of G20 Task Force Summit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberespionage Group Turla Deploys Backdoor Ahead of G20 Task Force Summit
-
Turla APT actor refreshes KopiLuwak JavaScript backdoor for use in G20-themed attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla APT actor refreshes KopiLuwak JavaScript backdoor for use in G20-themed attack
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Variants of Agent.BTZ-ComRAT Found- The Threat That Hit The Pentagon In 2008 Still Evolving; Part 1-2
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Gazing at Gazer
-
Turla’s watering hole campaign- An updated Firefox extension abusing Instagram
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Turla’s watering hole campaign- An updated Firefox extension abusing Instagram
-
Snake malware ported from Windows to Mac
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Snake malware ported from Windows to Mac
-
Snake- Coming soon in Mac OS X flavour
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Snake- Coming soon in Mac OS X flavour
-
Kazuar: Multiplatform Espionage Backdoor with API Access - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Kazuar: Multiplatform Espionage Backdoor with API Access - Palo Alto Networks Blog
-
Kazuar- Multiplatform Espionage Backdoor with API Access
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kazuar- Multiplatform Espionage Backdoor with API Access
-
Moonlight Maze- Lessons from history
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Moonlight Maze- Lessons from history
-
Carbon Paper: Peering into Turla second stage backdoor
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Carbon Paper: Peering into Turla second stage backdoor
-
Carbon Paper- Peering into Turla’s second stage backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Carbon Paper- Peering into Turla’s second stage backdoor
-
KopiLuwak- A New JavaScript Payload from Turla
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor KopiLuwak- A New JavaScript Payload from Turla
-
Bartholomew-GuerreroSaade-VB2016.indd
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bartholomew-GuerreroSaade-VB2016.indd
-
Running for Office_ Russian APT Toolkits Revealed
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Running for Office_ Russian APT Toolkits Revealed
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Pacifier APT
-
APT Case RUAG Technical Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Case RUAG Technical Report
-
APT Case RUAG Technical Report
The link to Mirror on Box failed its last check. Detailsfor APT Case RUAG Technical Report
-
The original link failed its last check. Original publisher Detailsfor BfV Cyber-Brief Nr. 02/2016
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Blockbuster
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor waterbug-attack-group
-
Russian group behind 2013 Foreign Ministry hack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian group behind 2013 Foreign Ministry hack
-
Cyber war in perspective: Russian aggression against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyber war in perspective: Russian aggression against Ukraine
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-witchcoven
-
Satellite Turla: APT Command and Control in the Sky - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Satellite Turla: APT Command and Control in the Sky - Securelist
-
Satellite Turla_ APT Command and Control in the Sky - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Satellite Turla_ APT Command and Control in the Sky - Securelist
-
Satellite Turla- APT Command and Control in the Sky
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Satellite Turla- APT Command and Control in the Sky
-
FireEye Intelligence: Threat Landscape Overview
The original link failed its last check. Original publisher Detailsfor FireEye Intelligence: Threat Landscape Overview
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Waterbug Attack Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of Project Cobra
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of Project Cobra
-
Weiterentwicklung anspruchsvoller Spyware- von Agent.BTZ zu ComRAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Weiterentwicklung anspruchsvoller Spyware- von Agent.BTZ zu ComRAT
-
Evolution of sophisticated spyware: from Agent.BTZ to ComRAT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Evolution of sophisticated spyware: from Agent.BTZ to ComRAT
-
New Pacifier APT Components Point to Russian-Linked Turla Group
The original link failed its last check. Detailsfor New Pacifier APT Components Point to Russian-Linked Turla Group
-
Linux Modules Connected to Turla APT Discovered
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Linux Modules Connected to Turla APT Discovered
-
Defending Against the Dragonfly Cyber Security Attacks v3.0.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Defending Against the Dragonfly Cyber Security Attacks v3.0.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The ‘Penquin’ Turla
-
The ‘Penquin’ Turla - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The ‘Penquin’ Turla - Securelist
-
The Regin Platform Nation-State Ownership Of Gsm Networks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Regin Platform Nation-State Ownership Of Gsm Networks
-
Regin- nation-state ownage of GSM networks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Regin- nation-state ownage of GSM networks
-
The Uroburos case: Agent.BTZ’s successor, ComRAT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Uroburos case: Agent.BTZ’s successor, ComRAT
-
The Uroburos case- new sophisticated RAT identified
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Uroburos case- new sophisticated RAT identified
-
The Darkhotel Apt A Story Of Unusual Hospitality v1.0
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Darkhotel Apt A Story Of Unusual Hospitality v1.0
-
Profiling An Enigma: The Mystery Of North Korea's Cyber Threat Landscape
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Profiling An Enigma: The Mystery Of North Korea's Cyber Threat Landscape
-
The Epic Turla Operation: Solving Some Of The Mysteries Of Snake/Uroboros
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Epic Turla Operation: Solving Some Of The Mysteries Of Snake/Uroboros
-
Sophisticated 'Turla' hackers spying on European governments, say researchers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sophisticated 'Turla' hackers spying on European governments, say researchers
-
The Epic Turla Operation - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Epic Turla Operation - Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Epic Turla Operation
-
Tr-25 Analysis - Turla / PNet / Snake/ Uroburos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tr-25 Analysis - Turla / PNet / Snake/ Uroburos
-
Analysis of Uroburos, using WinDbg
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of Uroburos, using WinDbg
-
Uroburos rootkit- Belgian Foreign Ministry stricken
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uroburos rootkit- Belgian Foreign Ministry stricken
-
The original link failed its last check. Original publisher Detailsfor Uroburos the Snake Rootkit
-
Agent.btz- a Source of Inspiration-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Agent.btz- a Source of Inspiration-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Turla
-
Uroburos – Deeper travel into kernel protection mitigation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uroburos – Deeper travel into kernel protection mitigation
-
Uroburos Highly Complex Espionage Software With Russian Roots
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Uroburos Highly Complex Espionage Software With Russian Roots
-
Uroburos - highly complex espionage software with Russian roots
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uroburos - highly complex espionage software with Russian roots
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kaspersky Lab and Seculert Announce ‘Madi,’ a Newly Discovered Cyber-Espionage Campaign in the Middle East
Newest first. Details opens the report in Explore.