Crutch is a Windows backdoor associated with the Russian state-sponsored Turla espionage group. It is designed for covert persistence, command-and-control through legitimate web services, and theft of files from compromised systems. A notable characteristic of Crutch is its use of Dropbox as a primary command-and-control and exfiltration channel via the Dropbox HTTP API, allowing operators to receive commands and upload stolen data while blending traffic with legitimate cloud-service use. Crutch has also used a hardcoded GitHub repository as a fallback communication channel to preserve access if the primary channel becomes unavailable.
Crutch supports multiple persistence mechanisms. It has been observed establishing persistence through scheduled tasks and through DLL search order hijacking involving legitimate applications such as Google Chrome, Mozilla Firefox, and Microsoft OneDrive. These techniques help the malware survive reboots and evade casual detection by abusing trusted software components and normal Windows tasking functionality.
The malware includes collection capabilities focused on files of intelligence value. It can monitor compromised hosts for removable-drive insertion, continuously watch removable media in a loop, and automatically copy files matching operator-defined extension criteria. Stolen material may be staged locally before transfer and then exfiltrated over the existing command-and-control channel. This behavior is consistent with espionage operations seeking documents from air-gapped or intermittently connected removable media.
Crutch is part of Turla’s long-running malware ecosystem and has been publicly linked alongside other Turla tooling such as TinyTurla and related backdoors. Its tradecraft reflects Turla’s preference for resilient command-and-control, stealthy persistence, and targeted document collection against high-value victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After Crutch and TinyTurla, Turla has now expanded its arsenal to include the TinyTurla-NG and TurlaPower-NG malware families...
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
Multiple actors and tools are described as using 7-Zip/WinRAR/zip/tar/gzip/makecab/PowerShell Compress-Archive to compress (often password-protect/encrypt) collected data prior to exfiltration (e.g., “used 7zip to archive extracted data in preparation for exfiltration”, “created password-protected RAR archives prior to exfiltration”, “used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data”).
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Several entries describe broader use of HTTP/HTTPS and related web mechanisms for C2, including "Crutch has conducted C2 communications with a Dropbox account using the HTTP API," "BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API," and "Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS."
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
"they use a compromised system inside the targeted network as a proxy, which forwards the traffic to the real C2 server."
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
APT41 used the Steam community page as a fallback mechanism for C2. Crutch has used a hardcoded GitHub repository as a fallback channel. MiniDuke uses Google Search to identify C2 servers if its primary C2 method via Twitter is not working.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
ADVSTORESHELL exfiltrates data over the same channel used for C2.
Ebury can exfiltrate SSH credentials through custom DNS queries.
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API)... ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files... OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration... ZIRCONIUM has exfiltrated files via the Dropbox API C2.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Turla backdoor used to maintain access, described as keeping the back door open.
A previously known Turla malware family referenced only as background to show expansion of Turla's arsenal.
Malware that uses a hardcoded fallback channel for command-and-control.
Malware capable of exfiltrating files from compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.