Epic Turla is a multi-stage Windows cyber-espionage malware operation and first-stage backdoor associated with the Turla threat actor, also tracked as Snake and Uroburos. The malware is also known by the names WorldCupSec, TadjMakhal, Wipbot, and Tavdig. It was used in broad espionage campaigns against government institutions, embassies, military organizations, research and education entities, pharmaceutical organizations, and foreign affairs targets, with notable concentration in Europe and the Middle East and extensive victimization across dozens of countries.
Epic Turla commonly served as an initial foothold and victim-selection platform that could later be upgraded to more advanced Turla tooling, including Carbon/Cobra, and in some cases operated in parallel with later-stage implants for communication resilience. Observed intrusion chains used spearphishing and watering-hole compromises, including malicious documents and social-engineering lures as well as exploitation of vulnerabilities such as CVE-2013-3346, CVE-2013-5065, and CVE-2012-1723. Campaigns attributed to Turla also used malicious Office macros to deploy JavaScript-based backdoors for reconnaissance and staging, reflecting the actor’s continued reliance on document-based delivery and selective post-compromise escalation.
The Epic Turla backdoor communicates over HTTP and supports remote configuration updates, system profiling, and command execution. Associated tooling and follow-on stages have been observed performing reconnaissance through extensive host and network enumeration, establishing persistence, stealing credentials, deploying rootkits, and enabling arbitrary command execution. Anti-analysis behavior includes checks for monitoring and packet-capture tools before continuing execution. Operational reporting also describes tiered command-and-control infrastructure using proxy layers and compromised servers to relay traffic and manage victim tasking.
Epic Turla is best understood as an espionage-oriented loader and backdoor ecosystem used by Turla to gain initial access, profile victims, maintain footholds, and transition selected targets to more capable long-term implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Over the last 10 months, Kaspersky Lab researchers have analyzed a massive cyber-espionage operation which we call 'Epic Turla'... The primary backdoor used in the Epic attacks is also known as 'WorldCupSec', 'TadjMakhal', 'Wipbot' or 'Tavdig'."
"Over the last 10 months, Kaspersky Lab researchers have analyzed a massive cyber-espionage operation which we call 'Epic Turla'... The primary backdoor used in the Epic attacks is also known as 'WorldCupSec', 'TadjMakhal', 'Wipbot' or 'Tavdig'."
"Over the last 10 months, Kaspersky Lab researchers have analyzed a massive cyber-espionage operation which we call 'Epic Turla'... The primary backdoor used in the Epic attacks is also known as 'WorldCupSec', 'TadjMakhal', 'Wipbot' or 'Tavdig'."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Targeting Ukraine, EU-related institutions, governments of EU countries, Ministries of Foreign Affairs globally, media companies and possibly corruption related targets in Russia, the group intensified their activity in 2014, which we described in our paper Epic Turla.
1 distinct technique documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Turla framework/campaign mentioned as historical background on the actor’s evolution.
Turla-associated malware referenced for using customized FNV-1a hashing for import resolution and for code similarities with Kazuar shellcode.
Referenced as another sophisticated cyberespionage platform used by threat actors.
Mentioned as another sophisticated cyberespionage platform for comparison with EquationDrug.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.