Epic, also known as Wipbot, WorldCupSec, TadjMakhal, and Tavdig, is a Windows backdoor associated with the Russian state-linked Turla espionage group. It has been used as an early-stage foothold and victim-profiling implant in targeted intrusions, particularly against government and diplomatic organizations in Europe, and has also appeared in broader Secret Blizzard activity reporting. Epic is commonly deployed through malicious Microsoft Office documents containing macros, after which it establishes execution on the victim host and begins host reconnaissance and operator communications.
Epic performs extensive discovery on compromised systems. Reported behaviors include enumerating running processes with tasklist, collecting the current username, querying system time and time zone information with net time, gathering NetBIOS and network context with nbtstat, surveying remote systems and shares with net view, and querying Windows Registry data with reg query. It also checks for security software or anti-malware services and may terminate itself if defensive products are detected, indicating built-in defense-evasion logic. The malware supports command handling from command-and-control infrastructure, including encrypted command exchange using a hardcoded key, and includes functionality to delete files on the victim machine.
In documented Turla operations, Epic has been delivered by macro-enabled lure documents and used as a first-stage implant before follow-on collection and monitoring. Related reporting describes JavaScript-based Turla intrusion chains using similar macro tradecraft for delivery of Wipbot-associated tooling, reinforcing its role in staged espionage operations. Turla has also used valid code-signing certificates to sign an Epic dropper, further supporting defense evasion and legitimacy masquerading. Overall, Epic is best characterized as a reconnaissance-oriented backdoor used to establish an initial covert presence, profile victims, and enable subsequent operator-directed activity on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The primary backdoor used in the Epic attacks is also known as “WorldCupSec”, “TadjMakhal”, “Wipbot” or “Tavdig”. | The attacks are known to have used at least two zero-day exploits: CVE-2013-5065 – Privilege escalation vulnerability in Windows XP and Windows 2003
CVE-2013-3346 – Arbitrary code-execution vulnerability in Adobe Reader
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The document contains a malicious macro, very similar to previous macros used by Turla in the past to deliver Wipbot, Skipper, and ICEDCOFFEE.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Turla-linked malware referenced in espionage reporting and later in historical Waterbug/Epic Turla reporting.
... Epic ... (v1.3→v1.4) ...
Epic (v1.3→v1.4)
A backdoor deployed via Amadey that serves as a staging component to drop Kazuar.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.