Cisco Talos reported that the Russia-linked Turla espionage group deployed a new lightweight backdoor, TinyTurla-NG, against Polish NGOs, including an organization supporting Ukraine. The malware acted as a fallback persistence mechanism, using compromised WordPress sites for command-and-control and supporting command execution, file transfer, shell switching, timing changes, and self-deletion. Talos also observed TurlaPower-NG PowerShell scripts used to collect and exfiltrate files, including key material tied to password-manager database protection, indicating an effort to steal credentials and preserve access inside targeted networks.
Other reporting tied Turla to parallel intrusions using similar stealth and persistence tradecraft. CERT-UA linked UAC-0024 activity against Ukraine’s defense sector to Turla, citing use of CAPIBAR, KAZUAR, COM hijacking, phishing documents, and exfiltration via rclone, while Cyble described a suspected Turla campaign in the Philippines that used malicious .LNK files, PowerShell, and MSBuild to install a tiny backdoor through scheduled-task persistence and compromised web infrastructure. Together, the reports show Turla continuing to expand its malware toolkit and reuse covert delivery, persistence, and credential-theft techniques across espionage operations aligned with Russian intelligence objectives.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Cyble described a campaign using malicious .LNK files disguised as PDFs to launch PowerShell, decrypt MSBuild payloads, and install a lightweight backdoor with scheduled-task persistence every 20 minutes. The report assessed with medium confidence that the activity was linked to Turla based on code and behavioral similarities to TinyTurla and use of a compromised Philippine news domain for C2.
Cisco Talos disclosed a Turla espionage campaign targeting Polish NGOs and identified the new TinyTurla-NG backdoor and associated TurlaPower-NG PowerShell exfiltration scripts. Talos assessed TinyTurla-NG as a 'last chance' persistence mechanism and documented capabilities including command execution, file transfer, self-deletion, and likely COM hijacking-based persistence.
Talos reported the TinyTurla-NG campaign targeting Polish NGOs was still active as recently as January 27, 2024. The operation used compromised vulnerable WordPress sites as command-and-control infrastructure and included TurlaPower-NG scripts for file collection and exfiltration.
Cisco Talos said the earliest observed compromise in the TinyTurla-NG campaign occurred on December 18, 2023, targeting a Polish NGO that worked to improve democracy and support Ukraine. Talos linked the activity to Turla and identified TinyTurla-NG as a lightweight persistence backdoor.
CERT-UA reported that since 2022 it has tracked a targeted espionage cluster as UAC-0024, primarily targeting Ukraine’s defense forces. The activity used CAPIBAR malware, sometimes deployed via compromised Microsoft Exchange servers, and in some intrusions also delivered the KAZUAR backdoor.
A joint NCSC and NSA advisory described Turla acquiring and using Iranian-origin Neuron and Nautilus implants, scanning for Iranian ASPX backdoors, and leveraging Iranian command-and-control infrastructure to expand access to additional victims, especially in the Middle East. Investigators also found Turla tested the Iranian tools on victims it had already compromised with Snake and used stolen cryptographic material and controller access to operate them.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
cyble.com
Open sourceblog.talosintelligence.com
Open sourcencsc.gov.uk
Open sourcewelivesecurity.com
Open sourceweb-assets.esetstatic.com
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.