ESET reported that the Turla espionage group deployed a stealthy backdoor that abuses Microsoft Outlook—and in older cases, The Bat! email client—as its command-and-control channel. The malware uses MAPI to access a victim’s mailbox without prompting for credentials, forwards outgoing messages to attacker-controlled addresses, records metadata from incoming mail, and hides within normal communications by sending stolen data in specially crafted PDF attachments while also receiving commands through PDFs.
The backdoor was linked to compromises involving the German Foreign Office, two other European foreign ministries, and a large defense contractor, with activity traced back to at least 2013. ESET said the malware maintains persistence in Outlook through per-user COM object hijacking and includes multiple stealth features, including deleting attacker-related emails and suppressing Outlook notifications; researchers also noted that its command mechanism lacks sender authentication, creating a risk that other attackers could potentially hijack already infected systems if they know the command format.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
ESET found that a 2018 version of the Turla Outlook backdoor added the ability to run PowerShell commands via Empire PSInject without invoking powershell.exe. This marked a functional enhancement of the implant.
After initially compromising the Federal College of Public Administration, the attackers moved into the German Foreign Office network in March 2017. ESET linked this compromise to the Turla Outlook backdoor.
The German government intrusion was detected by German security services at the end of 2017. The compromise reportedly involved computers at the German Foreign Office.
According to the report, the intrusion affecting the German government began in 2016. The campaign was later associated with Turla's Outlook backdoor activity.
ESET reported that the Turla email-based Outlook backdoor had been observed in real-world use since at least 2013. The implant used email and crafted PDF attachments for command-and-control and data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.