Penquin Turla

First seen
2014-01-01 00:00:00
Malware type
backdoor, rootkit
Family
Malware family
Profile updated
2026-07-07 12:59:10

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:ru country_code:us country_code:de country_code:fr

Context

Penquin Turla is a sophisticated Linux malware associated with the Turla APT group. It acts as a stealthy backdoor and has been used to target government and energy sectors. The malware is noted for its complex rootkit capabilities and evasion techniques.

Reports & references

  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • Kaspersky — 97937 (report)
  • leonardo.com — Malware+Technical+Insight+ Turla+%E2%80%9Cpenquin X64%E2%80%9D (report)
  • Kaspersky — 98440 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Penquin Turla (report)
  • twitter.com — 944741575837528064 (report)
  • Kaspersky — Penquins Moonlit Maze Pdf Eng (report)
  • media.kasperskycontenthub.com — Penquins Moonlit Maze Pdf Eng (report)
  • lab52.io — Looking For Penquins In The Wild (report)
  • blackberry.com — Pdfviewer (report)
  • leonardocompany.com — Malware+Technical+Insight+ Turla+%E2%80%9Cpenquin X64%E2%80%9D (report)
  • youtube.com — Watch (report)
  • Kaspersky — 97239 (report)
  • Kaspersky — Penquins Moonlit Maze Appendixb (report)

External references