HyperStack is a custom Windows backdoor used by the Russian state-sponsored Turla espionage group. It has been observed in intrusions against government organizations and is part of a broader Turla toolset that has included Carbon and Kazuar. HyperStack is an RPC-based backdoor designed for stealthy remote command execution, persistence, and movement within Windows networks.
HyperStack uses named pipes to receive and execute remote procedure call commands from an operator-controlled system. It has been documented modifying system configuration to make its communication pipe anonymously accessible and to permit anonymous enumeration of remote resources, enabling operation over SMB/RPC mechanisms. It can connect to remote IPC$ shares, enumerate account names on remote shares, detect incoming named-pipe connections, and use remote-share connectivity to forward commands to other systems. These behaviors support lateral movement inside compromised environments.
The malware has also been associated with service-based persistence and long-term access on infected hosts. Reporting has described it installing itself as a Windows service with elevated privileges and storing configuration data locally. HyperStack has used RSA encryption to protect command-and-control communications. In Turla operations, RPC-based backdoors including HyperStack were used alongside remote administration trojans to execute commands, transmit results, and exfiltrate data from victim networks.
HyperStack is most strongly associated with espionage activity targeting government entities, fitting Turla’s long-running pattern of maintaining covert, redundant access in high-value diplomatic and governmental networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turla uses HyperStack, Carbon, and Kazuar to compromise government entity.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK techniques Tactic Technique ID Technique name Execution T1059 ... Command-line Interface
MITRE ATT&CK techniques ... Discovery ... T1012 Query Registry ... Upon execution, HyperStack undergoes a similar registry key check ... and updates the same registry key to determine which named pipes can be accessed anonymously.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
MITRE ATT&CK techniques ... Command and Control ... T1001 Data Obfuscation ... When accessing the Pastebin URL, an encrypted blob is downloaded that requires a corresponding RSA private key from the configuration file.
Accenture researchers recently identified novel command and control (C&C) configurations for Turla’s Carbon and Kazuar backdoors on the same victim network.
attackers used a combination of recently updated remote administration trojans (RATs) and remote procedure call (RPC)-based backdoors including HyperStack
To compromise the organization's network, the attackers used a combination of recently updated remote administration trojans (RATs) and remote procedure call (RPC)-based backdoors including HyperStack
the attackers used a combination of recently updated remote administration trojans (RATs) and remote procedure call (RPC)-based backdoors
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can connect to remote IPC$ shares.
Malware that uses Windows APIs to detect incoming connections and access remote shares.
Backdoor that uses RSA encryption for C2 communications.
HyperStack is named in a reference title as malware/tooling used by Turla to compromise a government entity; no further detail is provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.