TinyTurla

MITRE ATT&CK: S0668 View on attack.mitre.org

Aliases: TinyTurla

First seen
2020-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Related IoCs
2 (2 malicious)
Last IoC activity
2024-12-07 16:20:03
Profile updated
2026-07-07 13:19:45

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:us country_code:de country_code:af

Context

TinyTurla is a backdoor that has been used by Turla against targets in the US, Germany, and Afghanistan since at least 2020.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to TinyTurla (S0668). The 2 most recently updated:

TypeIndicatorUpdatedSources
hostname connectotels.net 2024-12-07 1
hostname hostelhotels.net 2024-12-07 1

Detection coverage

  • 3 YARA rules
  • 297 Sigma rules

Malware & tools used

  • Asymmetric Cryptography (attack-pattern)
  • Native API (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Service Execution (attack-pattern)
  • Modify Registry (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Scheduled Transfer (attack-pattern)
  • Query Registry (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Data from Local System (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Tinyturla_Ng_Auto (yara-rule)
  • SEKOIA_Backoor_Win_Tinyturla_Ng (yara-rule)
  • SIGNATURE_BASE_APT_MAL_Tinyturla_Sep21_1 (yara-rule)

Reports & references

  • Cisco Talos — Tinyturla (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tiny Turla (report)
  • infosec.exchange — 111109357153515214 (report)
  • cybergeeks.tech — A Step By Step Analysis Of The Russian Apt Turla Backdoor Called Tinyturla (report)
  • MITRE ATT&CK — S0668 (report)

External references