Researchers reported a newly observed Trojan linked by shared code to the COMpfun malware family and assessed with medium-to-low confidence as associated with Turla. The campaign targeted diplomatic entities in Europe and began with a spoofed visa application used as the initial dropper, apparently obtained from a LAN shared directory. The malware stood out for using unusual HTTP/HTTPS response codes—including 402 and 422 through 429—as part of its command-and-control channel to queue and trigger attacker commands.
Once installed, the Trojan could fingerprint infected hosts, log keystrokes, steal clipboard data, capture screenshots, propagate via USB, enumerate network resources, and maintain persistence through COM hijacking. It also used anti-analysis checks to detect virtual machines, debuggers, and monitoring tools, and could inject into Windows, security, or browser processes. Communications and stored data were protected with RSA, AES-128, XOR, and LZNT1 compression, underscoring the malware’s technically distinctive evolution within the COMpfun toolset.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers observed a new Trojan in November 2019 that shared a code base with COMpfun and was assessed with medium-to-low confidence as linked to Turla. The campaign targeted diplomatic entities in Europe and used a spoofed visa application from a LAN shared directory as the initial dropper.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.