4 ms·
Details via: https://securelist.com/blog/research/67962/the-penquin-turla-2/ https://securelist.com/blog/research/67962/the-penquin-turla... Notably, the C&C d
by semenko 12y ago
Details via:
https://securelist.com/blog/research/67962/the-penquin-turla-2/ https://securelist.com/blog/research/67962/the-penquin-turla...
Notably, the C&C domain has been sinkholed by Kaspersky.
This has been linked to the complex "Turla" industrial espionage malware, as it shares a C&C server. (Turla: http://securelist.com/analysis/publications/65545/the-epic-turla-operation/ http://securelist.com/analysis/publications/65545/the-epic-t... )
- dsl 12y agoThe Turla malware sends data back using PHP proxies running on hacked servers. The same PHP proxy script is used by MiniDuke. MiniDuke in turn screams Russia in its target selection and spear phishing related to the Ukrainian bid to join NATO.