Carbon is a Turla-associated modular backdoor framework, also referred to in the content as the "Carbon system" and "Cobra." It has been used by the Turla threat actor for several years in cyber-espionage operations, including targeting embassies, foreign affairs institutions, and government organizations. The malware is described as a sophisticated next-level espionage platform with advanced peer-to-peer capability.
Observed capabilities in the provided content include Windows Registry enumeration, collection staging to a base directory containing gathered files and folders, decryption of task and configuration files for execution, and remote system and network discovery using commands such as net view, ipconfig -all, nbtstat, netstat -r, and netstat -an. Carbon can establish persistence by creating a Windows service whose name is based on the victim operating system version, and it can also create several scheduled tasks for later execution to maintain persistence.
For command and control, Carbon has used HTTP communications and has also used TCP and UDP. The content states that Carbon has used RSA encryption for C2 communications. In one reported Turla intrusion against a European government organization, a Carbon instance used traditional C2 URLs together with a Pastebin-based rendezvous mechanism to receive encrypted tasks. According to the content, the Carbon installer in that case dropped a Carbon Orchestrator, two communication modules, and an encrypted configuration file. The configuration included a [RENDEZVOUS_POINT] parameter referencing a Pastebin project, and the Pastebin content was an encrypted blob requiring an RSA private key from the configuration for decryption.
The content links Carbon to Turla infrastructure and operations alongside Kazuar and HyperStack on the same victim network. Reported Carbon-related indicators in the content include the URLs www.berlinguas[.]com/wp-content/languages/index.php, www.balletmaniacs[.]com/wp-includes/fonts/icons/, pastebin[.]com:443/raw/5qXBPmAZ, and the named pipe suplexrpc.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Accenture researchers recently identified novel command and control (C&C) configurations for Turla’s Carbon and Kazuar backdoors on the same victim network.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.
"Carbon uses the netstat -r and netstat -an commands."
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
MITRE ATT&CK techniques ... Command and Control ... T1001 Data Obfuscation ... When accessing the Pastebin URL, an encrypted blob is downloaded that requires a corresponding RSA private key from the configuration file.
the Carbon instance had been updated to include a Pastebin project to receive encrypted tasks alongside its traditional HTTP C&C infrastructure. | Accenture researchers recently identified novel command and control (C&C) configurations for Turla’s Carbon and Kazuar backdoors on the same victim network.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
MITRE ATT&CK techniques ... Command and Control ... T1090 Proxy ... The October sample likely acts as a transfer agent used to proxy commands from the remote Turla operators to the Kazuar instances on internal nodes in the network via an internet-facing shared network location.
MITRE ATT&CK techniques ... Command and Control T1102 ... Web Service ... Turla has relied on traditional C&C implementations, using compromised web servers as C&C, as well as utilizing legitimate web services like Pastebin.
To compromise the organization's network, the attackers used a combination of recently updated remote administration trojans (RATs) and remote procedure call (RPC)-based backdoors including HyperStack
the attackers used a combination of recently updated remote administration trojans (RATs) and remote procedure call (RPC)-based backdoors
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Examples include: "encrypts some C2 with RSA", "RSA encryption for C2 communications", "hard-coded RSA public key", "RSA-2048", "RSA-4096", and "REvil has encrypted C2 communications with the ECIES algorithm". | Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Turla backdoor observed with updated C2 functionality, including use of a Pastebin project to receive encrypted tasks alongside traditional HTTP C2 infrastructure.
Modular Turla backdoor framework with advanced peer-to-peer capability used for command execution, exfiltration, and resilient command-and-control. In the described campaign it used traditional compromised web servers plus Pastebin-hosted encrypted tasking.
Backdoor that creates multiple scheduled tasks for persistence.
A malware system referenced as part of MAKERSMARK/Turla tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.