Remove turla-uses-old-malware-attack-ukrainians
article thumbnail

Turla Uses Old Malware Infrastructure to Attack Ukrainian Institutions

Heimadal Security

Turla Russian espionage group delivers KOPILUWAK reconnaissance utility and QUIETCANARY backdoor to ANDROMEDA malware victims in Ukraine. Turla is also known as Iron Hunter, Krypton, Uroburos, Venomous Bear, or Waterbug and is thought to be sponsored by the Russian state. Cyber researchers track the operation as UNC4210.

Malware 95
article thumbnail

Tomiris called, they want their Turla malware back

SecureList

Our initial report described links between a Tomiris Golang implant and SUNSHUTTLE (which has been associated to NOBELIUM / APT29/TheDukes ) as well as Kazuar (which has been associated to Turla ); however, interpreting these connections proved difficult. Actor profile Tomiris focuses on intelligence gathering in Central Asia.

Malware 89