Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Turla turns PowerShell into a weapon in attacks against EU diplomats
#1
Quote:A cyberespionage group believed to be from Russia is once again striking political targets, and this time, PowerShell scripts have been weaponized to increase the power of their attacks.
 
Turla, also known as Snake or Uroburos, has been active since at least 2008. The advanced persistent threat (APT) group was previously linked to a backdoor implanted in Germany's Federal Foreign Office for the purposes of data exfiltration in 2017, alongside attacks against the US military, a defense contractor, and a variety of European government entities.

The Russian hacking group is rarely quiet for long, and now, the APT has returned with a fresh wave of attacks against diplomatic entities in Eastern Europe.

According to researchers from ESET, Turla has recently employed PowerShell scripts. The scripts allow "direct, in-memory loading and execution of malware executables and libraries," the team says, which can also help them circumvent discovery on victim machines when a malicious executable is dropped on to a disk.

SOURCE: https://www.zdnet.com/article/turla-turn...diplomats/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft is testing new features in Win...
It appears that Mi...harlan4096 — 09:24
Sysinternals Suite 06.17.2024
Changes in 06.17.2...harlan4096 — 06:22
Microsoft Edge 126.0.2592.61
Version 126.0.2592...harlan4096 — 06:21
GFYI [Official] AIDA64 Extreme Mother's...
Winners, please have...jasonX — 06:06
GFYI [Official] EaseUS Todo Backup Home...
ALL WINNERS HAVE BEE...jasonX — 06:03

[-]
Birthdays
Today's Birthdays
avatar (37)biobdam
Upcoming Birthdays
avatar (37)Tedscolo
avatar (44)brakasig
avatar (38)storoBox
avatar (46)kinotHeemn
avatar (37)Ceballos1976
avatar (38)efynu

[-]
Online Staff
kubik67's profile kubik67

>