Kazuar is a .NET-based backdoor associated with espionage activity and widely linked to the Turla threat actor. It is designed primarily for Windows and provides remote operators with broad control over compromised hosts, including command execution, file upload and download, screenshot capture, webcam capture, process enumeration, process termination, system information gathering, and malware updating. Kazuar also supports remotely loaded plugins, indicating an extensible post-compromise framework.
On Windows, Kazuar uses multiple persistence mechanisms, including Registry autoruns and Startup-folder shortcut creation, and it can also install itself as a service. It employs process injection by writing a DLL to disk and injecting it into explorer.exe, with support for execution inside specified processes. For host profiling and operator situational awareness, Kazuar gathers user information, network adapter details, and running process information, using WMI on Windows and native shell commands on Unix-like systems. It can also delete files as part of cleanup or task execution.
Kazuar supports command-and-control over multiple protocols, including HTTP, HTTPS, FTP, and FTPS, and can be configured with multiple command-and-control URLs for resilience. Observed variants encode communications with Base64 and parse structured tasking from the server. A notable feature is a built-in webserver that exposes an API on the infected host, allowing operators to submit tasks and retrieve results directly through inbound HTTP requests.
The malware has been assessed as a Turla-linked implant and has been discussed in relation to other Turla tooling such as Carbon and Gazer. It has also appeared in reporting on operations affecting government and defense-related targets, including activity involving Ukrainian entities. Code paths indicating Unix-like platform handling suggest cross-platform intent, but high-confidence operational use is best established on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky has published a report where they describe technical similarities between the SUNBURST malware and a previously identified .NET backdoor malware known as Kazuar.
Gamaredon used its library of loaders to provide initial access for Turla's heftier exploitation framework, Kazuar.
...на уражені ЕОМ довантажується складний багатофункціональний бекдор KAZUAR, в якому реалізовано більше 40 функцій...
...угрупуванням UAC-0028 (APT28) та UAC-0003 (Turla), зокрема, із застосуванням модифікованого флагманського шкідливого програмного забезпечення KAZUAR.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Kazuar’s ‘cmd’ command will run commands using “cmd.exe” for Windows systems and “/bin/bash” for Unix systems.
If the malware was executed with the "install" command-line argument, which uses .NET Framwork’s InstallHelper method to install the malware as a service. If the malware is started in a non-user interactive environment (no user interface), the malware installs itself as a service.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
If no arguments are provided and the malware determines it is running in a Windows environment, it saves a DLL to the system that it injects into the explorer.exe process.
If the malware was executed with the "install" command-line argument, which uses .NET Framwork’s InstallHelper method to install the malware as a service. If the malware is started in a non-user interactive environment (no user interface), the malware installs itself as a service.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
In April 2025, STOCKSTAY adopted a new string obfuscation method based on a pseudo-random algorithm called Squirrel3... GTIG tracks this as K1MORPHER.
Originally disguised as a stock market application, the malware has more recently masqueraded as legitimate software such as PDF readers and calculator programs.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Kazuar has the capabilities to use multiple protocols, such as HTTP, HTTPS, FTP or FTPS, determined by the prefixes of the hardcoded C2 URLs. So far, we have only observed HTTP used as the C2 protocol in our sample set.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
106 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor attributed in cited reporting to Turla; referenced only as a comparative example of cross-group malware deployment.
Custom malware family associated with Turla that has continued to evolve and remained in use in 2026 for espionage activity.
A longer-running Turla espionage toolkit/backdoor that shares architectural and development similarities with STOCKSTAY, including multi-component design, environmental keying, and overlapping obfuscation code.
A known Turla implant referenced as sharing code and functionality overlap with StockStay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.