Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Previous advisories from the NCSC detailed Turla’s use of Neuron and Nautilus implants... Since those advisories were published, the NCSC, NSA and partner-shared analysis of additional victims and infrastructure determined the Neuron and Nautilus tools were very likely Iranian in origin.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Turla malware/tool referenced alongside Nautilus in victim expansion operations.
An Iranian-origin implant/backdoor later used by Turla after acquiring the tooling and associated access material; Turla deployed it against additional victims and also used code needed to build versions of Neuron independently of Iranian C2 infrastructure.
A Turla backdoor previously used against email servers, but not specifically designed to integrate with Microsoft Exchange like LightNeuron.
A tool publicly linked to IRON HUNTER/Turla, later assessed by NCSC as very likely Iranian in origin and acquired/operated by IRON HUNTER.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.