IronNetInjector is a Turla malware loading toolchain that uses a Bring Your Own Interpreter approach centered on malicious IronPython scripts to decrypt, load, and execute additional Turla payloads in memory on Windows systems. The framework combines obfuscated IronPython components with an embedded .NET injector, referred to internally as NetInjector or PeInjector_x64, and encrypted follow-on payloads that have most commonly included ComRAT, with at least one observed case involving an RPC backdoor.
The IronPython scripts accept a decryption key as an argument and use Base64 plus Rijndael to recover embedded components. They then load the injector into memory through .NET reflection and use it to inject payloads either into the current interpreter process or into remote processes such as explorer.exe. The injector supports reflective PE injection of native payloads, and newer variants can also inject .NET assemblies into unmanaged processes. IronNetInjector can identify candidate target processes through native .NET process enumeration methods or by invoking tasklist and parsing the results.
For persistence and automated execution, IronNetInjector has been deployed with Windows Scheduled Tasks configured to launch the IronPython interpreter at logon, startup, or in response to specific system events. Related task configurations have been disguised with legitimate-looking service-style naming. This tradecraft aligns with Turla’s long-running emphasis on stealthy in-memory execution, process injection, and masqueraded persistence mechanisms. The toolchain appears intended to reduce reliance on PowerShell-based loaders and thereby evade defenses focused on PowerShell abuse and AMSI-monitored execution paths.
IronNetInjector is associated with Russian state-linked Turla espionage operations. Its role is primarily as an in-memory loader and injector that stages other implants rather than serving as the final espionage payload itself. Observed downstream payloads and Turla’s broader targeting history indicate likely use against government, diplomatic, defense, and other high-value espionage targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2021-02-19 ⋅ Palo Alto Networks Unit 42 IronNetInjector: Turla’s New Malware Loading Tool Agent.BTZ IronNetInjector TurlaRPC
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loading tool used by Turla to load or deploy other payloads.
Injector malware/tool that uses IronPython and a .NET injector to inject payloads into local or remote processes.
Malware that decrypts embedded .NET and PE payloads.
Malware that injects its DLL into running processes including explorer.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.