Topinambour is a Turla-associated espionage malware family/toolset, also referred to as Sunchoke in the provided reporting. The content describes it as a pure spy tool used by the Russia-linked Turla threat actor in campaigns active from early 2019, including operations against government and diplomatic entities. It was reportedly used against Austrian government infrastructure, where reporting described a fileless intrusion chain assembled inside the target network using short .NET or PowerShell command sequences, legitimate Windows components such as cmd.exe, and a four-byte TCP request to retrieve a dropper that installed a Turla trojan.
The campaign used trojanized legitimate installers, including SoftEther VPN 4.12, Psiphon3, and Microsoft Office activators, to deliver the Topinambour dropper. The dropper contains a small .NET shell that waits for Windows shell commands from operators. Operators then used SMB shares on rented VPS infrastructure and Windows commands such as net use and copy to move additional modules. The tooling was designed to support a fileless module chain by storing encrypted payload components in Windows registry values and using scheduled tasks for persistence.
Associated payloads and related modules described in the content include delivery of the known KopiLuwak JavaScript trojan, a .NET trojan referred to as RocketMan, and a PowerShell trojan referred to as MiamiBeach. Reported capabilities across these modules include uploading, downloading, and executing files, system fingerprinting, and in the PowerShell variant, taking screenshots. The .NET trojan command set is listed as #down, #upload, #timeout, #stop, and #sync; the PowerShell trojan command set is listed as #upload, #down, #screen, #timeout, #stop, and #sync.
Command-and-control infrastructure included compromised legitimate WordPress sites hosting actor PHP scripts, as well as rented VPS infrastructure reported in South Africa with external IPs beginning with 197.168. The content states that the .NET and PowerShell trojans used RC4-encrypted communications. Reported artifacts and indicators include strings such as TrumpTower, RocketMan!, and MiamiBeach; a Topinambour dropper sample named topinambour.exe with SHA-256 8bcf125b442f86d24789b37ce64d125b54668bc4608f49828392b5b66e364284 and MD5 110195ff4d7298ba9a186335c55b2d1f; a dropped payload at %LOCALAPPDATA%/VirtualStore/certcheck.exe; persistence via a scheduled task running every 30 minutes; and a decoy application dropped to %TEMP%/activator.exe. Related reporting also notes a KopiLuwak scheduled task named ProactiveScan with description NTFS Volume Health Scan, and compromised WordPress paths resembling /wp-includes/Requests/Socks.php.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ORF reported in mid-January that the attack bore the hallmarks of Russia's Turla Group. Citing information from its own sources, the broadcaster described the attack in detail: Like all previously known malware modules that are assigned to Turla, Topinambour is a pure spy tool.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware used for persistent access and in-memory execution of additional payloads, deployed by Turla APT group against government and diplomatic targets.
A Turla-attributed espionage malware module described as a pure spy tool. It uses short command chains for .NET or PowerShell, relies on legitimate Windows components such as cmd.exe, and was deployed in a fileless manner. A command-line module sent a four-byte TCP request to an external server, which downloaded a dropper that then placed the trojan.
A Turla-associated .NET toolset delivered via trojanized legitimate installers. It drops a small .NET remote shell, establishes persistence via scheduled tasks, uses SMB shares for staging, and delivers follow-on modules including KopiLuwak and analogous .NET/PowerShell trojans to build a largely fileless registry-based RAT chain (upload/download/execute, host fingerprinting; PowerShell variant can screenshot).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.