Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Russian hackers used TinyTurla-NG to breach European NGO’s systems
    Cyber Security

    Russian hackers used TinyTurla-NG to breach European NGO’s systems

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 21, 2024Editorial DepartmentThreat Intelligence/Malware

    Russian hackers

    The Russia-linked threat actor Turla infected multiple systems of an unnamed European non-governmental organization (NGO) in order to deploy a backdoor called Turla. TinyTurla-NG.

    “As part of their initial post-compromise actions, the attackers compromised the first system, established persistence, and added exclusions to the antivirus products running on these endpoints,” Cisco Talos said in a new report released today. Part of it.”

    “Turla then opened additional communication channels through Chisel for the data exfiltration and redirection to other accessible systems in the network.”

    There is evidence that infected systems were compromised as early as October 2023, Chisel was deployed in December 2023, and a data exfiltration occurred through the tool a month later (around January 12, 2024).

    Internet security

    TinyTurla-NG was first documented by the cybersecurity firm last month after it was found to be linked to cyberattacks against a Polish NGO working to improve democracy in Poland and support Ukraine during the Russian invasion .

    Ciscotalos told The Hacker News at the time that the campaign appeared to be highly targeted, targeting a small number of organizations, most of which were based in Poland.

    Russian hackers

    The attack chain involves Turla using its initial access rights to configure Microsoft Defender antivirus exclusions to evade detection and delete TinyTurla-NG, and then persist it by creating a malicious “sdm” service disguised as the “System Device Administrator” service the service.

    TinyTurla-NG acts as a backdoor to conduct subsequent reconnaissance, exfiltrate files of interest to a command and control (C2) server, and deploy a customized version of the Chisel tunneling software. The exact route of entry is still under investigation.

    “Once the attackers gain access to a new box, they repeat the campaign of creating Microsoft Defender exclusions, removing malware components, and creating persistence,” Talos researchers said.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.