Researchers and incident responders linked multiple stealth backdoors to Turla, showing how the group maintains covert access across both Linux and Windows environments. Analysis of Penquin, a Linux backdoor tied to Turla, found that it does not contain a hardcoded command-and-control server; instead, it waits for a specially crafted network packet, extracts the C2 address from that trigger, and then initiates contact. By recreating the malware’s packet-validation logic and extending detection from UDP to TCP header fields, researchers scanned internet-facing systems and identified 86 IP addresses believed to host Penquin, many on vulnerable VPS infrastructure in Europe, Russia, and the United States. The findings support assessments that compromised servers were used as relay or command infrastructure for broader Turla activity, including links to TinyTurla and operations targeting the Korean defense sector.
Separate reporting on TinyTurla described a lightweight Windows backdoor used as a “second-chance” persistence mechanism when primary malware is removed. The malware masquerades as Windows Time Service, runs as w64time.dll under svchost.exe, and beacons over HTTPS at short intervals while supporting file transfer and remote process execution; observed victims included systems in the United States, Germany, and Afghanistan. Historical forensic work further tied Penquin to older LOKI2-derived Unix tooling recovered from the Moonlight Maze espionage campaign, reinforcing the long-running lineage between Moonlight Maze and modern Turla operations and showing the group’s continued reliance on covert relay infrastructure, trojanized system components, and low-noise persistence techniques.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
After a first scan in June 2020, researchers identified 86 IP addresses hosting Penquin. The detected systems were concentrated in Europe, Russia, and the United States, with many appearing to be vulnerable VPS hosts.
The Lab52 article says Leonardo analysts published an in-depth 2020 analysis of Penquin focused on a new 64-bit sample. The work documented the malware's activation packet structure and protocol.
Cisco Talos said its telemetry indicated the TinyTurla backdoor had been used since at least 2020. Talos assessed it was likely deployed as a stealthy second-chance persistence mechanism.
Swiss GovCERT's 2016 RUAG report is cited as the first public in-the-wild confirmation of Penquin Turla. It showed Turla using a trojanized ntpd component to maintain covert access after cleanup of an earlier intrusion.
The Kaspersky report states that Penquin Turla, a Linux backdoor associated with Turla, was originally discovered in late 2014. This established the malware as a known component of Turla operations.
According to an FBI FOIA release cited in the Kaspersky report, the FBI destroyed stored Moonlight Maze evidence, including computer disks, in February 2008. This affected preservation of original investigative material.
Kaspersky assessed that the Penquin Turla codebase showed signs of being exceptionally old and was developed and maintained from roughly 1999 to 2004. The report concluded the malware was based on the older LOKI2 backdoor lineage.
The report says HRTest, a UK relay server, was used by Moonlight Maze operators for about six months in late 1998 and early 1999. Artifacts preserved from this server later enabled reconstruction of attacker behavior and tooling.
By mid-1998, FBI and Department of Defense investigators had forensic evidence pointing to Russian ISPs in the Moonlight Maze investigation. This marked an early attribution milestone in the campaign.
The Kaspersky report states that Moonlight Maze intrusions began as early as 1996, targeting U.S. military and government networks. Victims included organizations such as NASA, Department of Energy laboratories, and multiple military facilities.
The Kaspersky report analyzed archived Moonlight Maze artifacts and argued that the actor likely evolved into the modern Turla APT. It also concluded that Penquin Turla derived from LOKI2 rather than cd00r, strengthening the historical continuity claim.
Lab52 described a method to detect internet-facing Penquin infections by recreating the malware's activation packet logic and extending scanning from UDP to TCP. The article reported that this approach could reveal compromised servers used as Turla infrastructure.
Cisco Talos reported a previously undiscovered backdoor attributed to Turla and described it as a Windows service DLL masquerading as 'Windows Time Service.' Talos also reported infections in the United States, Germany, and Afghanistan and published detection material including IOCs and a YARA rule.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
lab52.io
Open sourceblog.talosintelligence.com
Open sourcemedia.kasperskycontenthub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.