Researchers reported that Turla updated its JavaScript-based espionage tooling across multiple intrusion paths, including a G20-themed spearphishing lure and long-running watering-hole operations. Proofpoint identified a new .NET/MSIL dropper that used a likely legitimate G20 Digital Economy Taskforce PDF invitation as a decoy, then wrote a Stage 1 JavaScript file to disk, created persistence with a scheduled task, fingerprinted the host, and loaded the JS/KopiLuwak backdoor in memory. The malware communicated over HTTP POST with compromised legitimate websites and supported reconnaissance, arbitrary code execution, and file transfer, indicating use in early-stage intelligence collection against likely targets such as diplomats, journalists, and policymakers.
Separate reporting tied Turla to selective watering-hole compromises of legitimate, often embassy-related, websites that redirected chosen visitors to attacker infrastructure after browser and plugin fingerprinting. ESET also described an updated malicious Firefox extension linked to Turla that abused Instagram comments and a hidden bit.ly path for command-and-control discovery, while earlier research on the Epic Turla operation provides broader context for the group’s established cyber-espionage tradecraft. Together, the reports show Turla continuing to evolve stealthy first-stage access methods, blending decoy documents, compromised websites, social media, and legitimate web services to profile victims and deploy JavaScript backdoors.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
ESET reported that Turla had been using watering-hole techniques since at least 2014, compromising legitimate websites, often embassy-related, to profile and selectively target visitors. The activity focused on governments, officials, and diplomats.
Proofpoint said it had not observed the full attack in the wild and had found the MSIL dropper on a public malware repository, but warned the activity could be ongoing. The company notified CERT-Bund about the findings.
Proofpoint disclosed that the newer KopiLuwak variant communicated over HTTP POST with two compromised legitimate websites and used RC4 to encrypt traffic. The backdoor supported reconnaissance, arbitrary code execution, file upload, and file download.
Proofpoint reported that Turla was using a new .NET/MSIL dropper, internally named Runer.exe, to install a refreshed JavaScript-based KopiLuwak backdoor. The chain dropped a decoy PDF and JavaScript components, established persistence with a scheduled task, fingerprinted the host, and loaded the backdoor in memory.
Proofpoint analyzed a likely legitimate PDF invitation themed around a G20 Digital Economy Taskforce meeting scheduled for October in Hamburg, Germany. The lure was embedded in a new .NET/MSIL dropper used to deploy the JS/KopiLuwak backdoor.
ESET reported that the extracted URL http://bit.ly/2kdhuHX resolved to static.travelclothes.org/dolR_1ert.php, a Turla-associated watering-hole C2. Bit.ly statistics showed 17 hits in February, suggesting a limited test run.
ESET said the malicious Firefox extension derived a hidden bit.ly path from a comment on a Britney Spears Instagram post. The relevant comment was posted on February 6 and was used to recover the shortened C2 URL.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourcesecurelist.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.