Kaspersky reported that the Reductor Trojan, a malware family linked by code similarities to COMpfun and tentatively associated with Turla, compromised victims by patching browser and system pseudo-random number generator functions in memory. That let the malware insert encrypted, victim-specific identifiers into the TLS client_random field without altering packets directly, enabling operators to recognize encrypted sessions and potentially support interception workflows. The campaign primarily targeted users in Russia and Belarus, and Reductor also installed root certificates, supported remote certificate updates, and maintained persistence through an LSA notification package while communicating with command-and-control servers over HTTP POST using AES-128-encrypted host identifiers.
Investigators said victims were infected through trojanized software installers downloaded over HTTP from warez sites or through secondary delivery from systems already compromised by COMpfun. Kaspersky assessed that the attackers likely controlled victims’ network channels and replaced legitimate installers on the fly before delivery. The activity highlighted a stealthy persistence and traffic-marking approach consistent with techniques such as COM object hijacking and other low-visibility Windows persistence methods, underscoring how the operators combined installer tampering, certificate abuse, and in-memory browser manipulation to track and compromise protected web traffic.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Kaspersky said the Reductor campaign was active from the end of April 2019 through at least August 2019, targeting victims in Russia and Belarus. Infection occurred via trojanized software installers delivered over HTTP and via already infected COMpfun hosts.
Kaspersky discovered the Reductor malware family in April 2019. The malware was later linked by code similarities to the older COMpfun Trojan and tentatively associated with Turla.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.