TinyTurla
MITRE ATT&CK: S0668 View on attack.mitre.org
Aliases: TinyTurla
- First seen
- 2020-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2024-12-07 16:20:03
- Profile updated
- 2026-07-07 13:19:45
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:us country_code:de country_code:af
Context
TinyTurla is a backdoor that has been used by Turla against targets in the US, Germany, and Afghanistan since at least 2020.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to TinyTurla (S0668). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | connectotels.net | 2024-12-07 | 1 |
| hostname | hostelhotels.net | 2024-12-07 | 1 |
Detection coverage
- 3 YARA rules
- 297 Sigma rules
Malware & tools used
- Asymmetric Cryptography (attack-pattern)
- Native API (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Service Execution (attack-pattern)
- Modify Registry (attack-pattern)
- Windows Command Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Fileless Storage (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Scheduled Transfer (attack-pattern)
- Query Registry (attack-pattern)
- Fallback Channels (attack-pattern)
- Data from Local System (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- Turla (threat-actor)
Detection rules
- MALPEDIA_Win_Tinyturla_Ng_Auto (yara-rule)
- SEKOIA_Backoor_Win_Tinyturla_Ng (yara-rule)
- SIGNATURE_BASE_APT_MAL_Tinyturla_Sep21_1 (yara-rule)
Reports & references
- Cisco Talos — Tinyturla (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Tiny Turla (report)
- infosec.exchange — 111109357153515214 (report)
- cybergeeks.tech — A Step By Step Analysis Of The Russian Apt Turla Backdoor Called Tinyturla (report)
- MITRE ATT&CK — S0668 (report)