Investigators at Sophos X-Ops uncovered a long-running intrusion at a telecommunications company involving a stealthy backdoor they named NotSoTinyTurla, citing code and tradecraft overlaps with malware previously associated with Turla. The malicious component was identified as smpsvc.dll, likely resident since at least June 2022, and configured to launch via the legitimate smphost service so it could run covertly inside svchost.exe. Sophos said the malware used an obfuscated loader, generated unique command-and-control URLs, and reached out to infrastructure disguised as a Chartbeat domain before injecting its final payload directly into memory while obscuring API calls.
After establishing command and control, the intruders appeared to conduct a DCSync credential-theft operation and host discovery using Impacket, indicating an effort to expand access inside the victim environment. Investigators also found that the attackers created an SRService service to deploy cloudflared and maintain persistence through a Cloudflare Tunnel, a technique Sophos linked to prior Turla tradecraft. The findings add to the body of reporting on Turla’s multi-stage backdoor ecosystem, including earlier research into the group’s second-stage tooling such as Carbon, and suggest the actor continues to adapt established espionage methods for covert access and persistence.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On September 12, 2023, Sophos observed the legitimate smphost service running inside svchost.exe to load the malicious smpsvc.dll and execute attacker commands. This behavior matched the stealthy service-based loading technique highlighted in Sophos's analysis.
In mid-August 2023, Sophos X-Ops Incident Response responded to a cyber incident affecting a telecommunications company. After the customer was onboarded to Sophos MDR, analysts detected creation of a suspicious Cloudflared tunneling service and began investigating.
Sophos assessed that the malicious smpsvc.dll backdoor had likely been present in the telecommunications company's environment since at least June 2022. The DLL masqueraded as a legitimate SMP host service component and was configured to auto-start via the legitimate smphost service.
Sophos MDR Ops and SophosLabs researchers uncovered a backdoor they dubbed NotSoTinyTurla, assessed overlaps with Turla activity previously described by Cisco Talos, and identified follow-on actions including DCSync, Impacket discovery, and creation of the SRService service to deploy cloudflared for persistent access. Sophos said it disrupted the Cloudflare tunnel activity before further attacker actions occurred.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.