Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December 2014, Kaspersky announced the discovery of a Linux-based Turla toolkit named Penquin Turla.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux-focused Turla backdoor/platform discussed in multiple reports as part of long-running espionage operations.
Referenced as an example of Linux malware used to exploit enterprise visibility gaps; no further technical detail is provided in the content.
A Linux backdoor used by Turla for covert access and exfiltration. The content says it was compiled for older Linux kernel versions, was based on LOKI2, and retained features such as tasking files, covert channel communications, and promiscuous sniffers.
Penquin Turla is a Linux backdoor attributed to the Turla APT group. It is based on the cd00r backdoor concept and provides stealthy remote command execution and management capabilities. It uses raw packet capture and 'magic packets' for covert C2 communication, does not require root privileges to operate, and is designed to evade detection by common administrative tools like netstat. It is statically linked, stripped of symbols, and includes hardcoded C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.