ESET reported that the Turla espionage group deployed a unique backdoor that abused Microsoft Outlook to conduct covert operations against targets in Europe. The malware used Outlook as a communications channel, allowing operators to hide command-and-control activity inside normal email traffic and blend malicious actions with legitimate enterprise workflows.
The campaign was aimed at European institutions, underscoring Turla’s continued focus on long-term intelligence collection against government and diplomatic targets. By leveraging a trusted application already embedded in many organizations, the attackers reduced the likelihood of detection while maintaining persistent access for surveillance and data theft.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
ESET publicly reported on a unique Outlook-based backdoor used by the Turla APT group to spy on European government and diplomatic institutions. The disclosure described the malware's use of Microsoft Outlook functionality for command-and-control and data theft.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.