Kazuar is a long-running Turla espionage implant and backdoor framework used by the Russia-linked threat actor also tracked as Secret Blizzard and Venomous Bear. Active since at least the mid-2010s and still evolving in 2026, it has been used in cyberespionage operations against government, diplomatic, military, defense, justice, technology, and research targets, with especially notable activity involving Ukraine and European government environments.
Kazuar is a Windows-focused, fully featured post-compromise platform designed for stealthy, persistent intelligence collection. Reported capabilities include installation as a Windows service for persistence; command execution; system and user reconnaissance; collection of files and system information; theft of event log data; capture of authentication tokens, cookies, and credentials from browsers, FTP clients, VPN software, password managers, cloud tooling, and email clients; webcam image capture; and staging of collected data prior to exfiltration. Kazuar communicates with command-and-control infrastructure over HTTP and HTTPS, has used Base64-encoded communications, and in some variants can also expose an HTTP-based API or operate through internal proxying and multi-hop command paths. Compromised websites, including WordPress-based infrastructure, have been used in its command-and-control ecosystem.
More recent reporting describes Kazuar as having evolved from a monolithic backdoor into a modular espionage framework with specialized components for orchestration, communications brokering, and task execution. Documented functions in newer variants include anti-analysis checks, fragmented inter-process coordination, covert internal messaging, configurable transport selection, keylogging, screenshot capture, email monitoring, and encrypted staging and exfiltration workflows. Some delivery chains have used loaders or in-memory .NET components, and some payloads have been tied cryptographically to victim-specific attributes.
Kazuar is closely associated with Turla’s long-term intelligence operations and has appeared alongside other Turla tooling such as Carbon and HyperStack. Reporting from 2025 also indicates operational collaboration in which Gamaredon-provided access or loaders were used to deploy Kazuar on high-value Ukrainian targets. Overall, Kazuar is best understood as one of Turla’s flagship espionage backdoors for durable access, covert collection, and flexible post-exploitation in strategically important networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turla is associated with a collection of custom malware families, including Uroburos, also called Snake, and Kazuar. Researchers noted that Kazuar has continued to evolve and remained in use in 2026
Gamaredon used its library of loaders to provide initial access for Turla's heftier exploitation framework, Kazuar.
...на уражені ЕОМ довантажується складний багатофункціональний бекдор KAZUAR, в якому реалізовано більше 40 функцій...
...угрупуванням UAC-0028 (APT28) та UAC-0003 (Turla), зокрема, із застосуванням модифікованого флагманського шкідливого програмного забезпечення KAZUAR.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
Across incidents observed between February and June 2025, Gamaredon tooling, including PteroGraphin and PteroOdd, was used to deploy Turla’s Kazuar backdoor and, in at least one case, restore Turla’s access after the group appeared to have lost its foothold.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
A second method drops a lightweight .NET loader configured as a COM object, decrypting and executing the payload entirely in memory with almost no trace left on disk. | The malware uses hidden Windows messaging, named pipes, Mailslots, and Google Protocol Buffers for structured internal routing
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
In April 2025, STOCKSTAY adopted a new string obfuscation method based on a pseudo-random algorithm called Squirrel3... GTIG tracks this as K1MORPHER.
...steal authentication tokens, cookies, and credentials from a wide variety of programs, including browsers, FTP clients, VPN software, KeePass, Azure, AWS, and Outlook.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
GTIG conducted a review... in which we observed Turla deploying a wide range of tools into the victim’s network... via malicious GPO installation from a compromised domain controller... Multiple ZIP archives, each containing one of the core components of STOCKSTAY or its configuration, were uploaded to the domain controller.
...allows the threat actors to launch javascript on the device, steal data from event logs, steal information about systems files...
MITRE ATT&CK techniques ... Command and Control ... T1071 Standard Application Layer Protocol ... The C&C URLs correspond to compromised legitimate websites for Turla to proxy commands and exfiltrate data to Turla backend infrastructure.
Central to its operations is the STOCKSTAY.STOCKMARKET component, which serves as the primary orchestrator, managing command-and-control logic over secure WebSocket connections using the open-source websocket-sharp library.
MITRE ATT&CK techniques ... Command and Control ... T1090 Proxy ... The October sample likely acts as a transfer agent used to proxy commands from the remote Turla operators to the Kazuar instances on internal nodes in the network via an internet-facing shared network location.
MITRE ATT&CK techniques ... Command and Control T1102 ... Web Service ... Turla has relied on traditional C&C implementations, using compromised web servers as C&C, as well as utilizing legitimate web services like Pastebin.
Most of its new tools are simple downloaders... Gamaredon used its library of loaders to provide initial access for Turla's heftier exploitation framework, Kazuar.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
84 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware family associated with Turla that has continued to evolve and remained in use in 2026 for espionage activity.
A longer-running Turla espionage toolkit/backdoor that shares architectural and development similarities with STOCKSTAY, including multi-component design, environmental keying, and overlapping obfuscation code.
A known Turla implant referenced as sharing code and functionality overlap with StockStay.
A long-standing Turla implant/backdoor used since 2017. In this content it is described as architecturally similar to STOCKSTAY, with Kernel, Bridge, and Worker modules and multi-hop C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.