Penquin
MITRE ATT&CK: S0587 View on attack.mitre.org
Aliases: Penquin 2.0, Penquin_x64, Penquin
- First seen
- 2014-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- linux
- Profile updated
- 2026-07-07 13:19:48
Targeted industries: government-and-public-sector energy-and-utilities
Context
Penquin is a remote access trojan (RAT) with multiple versions used by Turla to target Linux systems since at least 2014.
Detection coverage
- 202 Sigma rules
Malware & tools used
- Unix Shell (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Traffic Signaling (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Cron (attack-pattern)
- Network Sniffing (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Indicator Removal from Tools (attack-pattern)
- Linux and Mac Permissions (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Socket Filters (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
Used by threat actors
- Turla (threat-actor)
Reports & references
- leonardo.com — Malware+Technical+Insight+ Turla+%E2%80%9Cpenquin X64%E2%80%9D (report)
- MITRE ATT&CK — S0587 (report)
- Kaspersky — 67962 (report)