Skipper is a Turla first-stage backdoor used in targeted cyberespionage operations against government, diplomatic, and related high-value organizations, particularly in Europe. It has been associated with spearphishing campaigns and with Firefox-extension-based intrusion chains linked to Turla. Public reporting places Skipper in multi-stage compromises where it provides the initial foothold and victim profiling before Turla deploys stealthier second-stage implants such as Gazer, Carbon, or Kazuar.
Skipper has been delivered through malicious Office macro documents in spearphishing operations and has also been linked to a malicious Firefox extension campaign previously tracked as Pacifier APT. In the browser-extension case, the extension acted as a JavaScript backdoor and was assessed to download Skipper, helping attribute that activity to Turla. Reporting also ties Skipper-related activity to campaigns sometimes referred to as WhiteAtlas.
As a first-stage implant, Skipper is used to establish persistence, collect host and environment information, and support follow-on tasking. Turla tradecraft associated with Skipper includes reconnaissance of infected systems, use of compromised legitimate websites for command-and-control, and staged deployment of more capable long-term espionage malware after initial compromise. The malware is part of Turla’s broader intrusion ecosystem, which has historically focused on ministries, embassies, consulates, diplomats, and other state-linked entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spearphishing delivers a first-stage backdoor such as Skipper; A second stealthier backdoor (Gazer in this instance, but past examples have included Carbon and Kazuar) is put in place.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2020-03-12 ⋅ ESET Research ⋅ Tracking Turla: New backdoor delivered via Armenian watering holes ...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Turla backdoor/tool used in cyber operations and watering-hole campaigns.
A Turla-associated malware/campaign referenced as part of the group's broader spear-phishing activity and as a payload delivered by similar macros.
A first-stage backdoor delivered via spearphishing in Turla-linked intrusion chains.
A known Turla backdoor malware family downloaded by the langpack-en-GB Firefox extension in the Pacifier campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.