ESET disclosed Gazer, a previously undocumented second-stage backdoor attributed to the Turla cyberespionage group, describing its use in targeted intrusions against governments, diplomats, embassies, consulates, and ministries. The victims were concentrated in Europe, with a particular focus on Southeastern Europe and countries of the former Soviet Union, and the malware had reportedly been active since at least 2016.
The backdoor was built for long-term covert access, using code-string changes, randomized markers, and secure file wiping to reduce detection while stealing information over extended periods. According to ESET, Turla typically began operations with spearphishing that deployed a first-stage implant such as Skipper, then escalated to stealthier payloads including Gazer, Carbon, or Kazuar, while relaying command-and-control traffic through compromised legitimate websites.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
ESET published research describing Gazer as an advanced second-stage backdoor used for long-term espionage and stated it was the first to document the malware publicly. The research attributed the campaigns to the Turla group based on similarities with prior operations and described spearphishing, first-stage backdoors such as Skipper, and compromised websites used as command-and-control proxies.
ESET reported evidence that the previously undocumented Gazer backdoor had been actively used since at least 2016 in targeted attacks against governments, diplomats, embassies, consulates, and ministries. The victims identified were concentrated in Europe, especially Southeastern Europe and former Soviet Union countries.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.