ICEDCOFFEE, also known as Shirime, is a Turla malware family used in targeted intrusion operations against government and government-affiliated organizations, particularly foreign ministries in Europe. It has been associated with Russian-speaking Turla activity and has appeared in campaigns leveraging malicious Microsoft Office documents and Office exploit chains for initial compromise.
ICEDCOFFEE is linked to Turla’s long-running spearphishing tradecraft and has been referenced alongside other Turla delivery frameworks and payloads. Turla macro tooling used to deploy other malware has been described as similar to mechanisms previously used with ICEDCOFFEE, indicating it forms part of the group’s established infection ecosystem. In 2017, ICEDCOFFEE was also reported as a payload delivered through exploitation of CVE-2017-0261 in attacks focused mainly on foreign ministries, governments, and related organizations.
Available reporting in this context does not provide a sufficiently detailed public technical profile of ICEDCOFFEE’s internal functionality to support a more specific malware classification or a broader set of capabilities at high confidence. What is clear is that it is an operational Turla payload used in targeted Windows-focused intrusion activity and delivered through spearphishing-style document lures and exploit-enabled Office attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Prior to this attack, Turla was also discovered using CVE-2017-0261 (a different EPS vulnerability).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This is a technique we’ve observed before with Turla’s ICEDCOFFEE payloads... While the delivery method is somewhat similar to ICEDCOFFEE, the JavaScript differs greatly and appears to have been created mainly to avoid detection.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously observed Turla JavaScript payload referenced for comparison because the new malware uses a similar macro-based delivery method.
Turla-associated backdoor/implant used as a payload in targeted operations.
Referenced as an earlier Turla JavaScript payload family used with similar macro-based delivery techniques; used as a comparison point for the newer JavaScript backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.