Kaspersky researchers reported that the Turla espionage group used commercial satellite internet connections to hide command-and-control traffic for malware operations. The attackers abused downstream-only satellite links and spoofed victim IP addresses so infected systems appeared to communicate with legitimate satellite subscribers, making the true location of the operators difficult to trace and allowing the infrastructure to blend into normal network noise.
The technique was tied to long-running Turla intrusions against government, military, diplomatic, and research targets, and showed a high level of operational security rather than a new malware family alone. By routing traffic through satellite providers and disposable access points, the group reduced attribution risk and complicated incident response, highlighting how advanced threat actors can combine conventional malware with unconventional communications infrastructure to sustain covert espionage campaigns.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published research describing the 'Satellite Turla' operation, detailing how the Turla APT used hijacked satellite internet links for command-and-control to help obscure its infrastructure.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.