Penquin Turla
- First seen
- 2014-01-01 00:00:00
- Malware type
- backdoor, rootkit
- Family
- Malware family
- Profile updated
- 2026-07-07 12:59:10
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:ru country_code:us country_code:de country_code:fr
Context
Penquin Turla is a sophisticated Linux malware associated with the Turla APT group. It acts as a stealthy backdoor and has been used to target government and energy sectors. The malware is noted for its complex rootkit capabilities and evasion techniques.
Reports & references
- intezer.com — Top Linux Cloud Threats Of 2020 (report)
- Kaspersky — 97937 (report)
- leonardo.com — Malware+Technical+Insight+ Turla+%E2%80%9Cpenquin X64%E2%80%9D (report)
- Kaspersky — 98440 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Penquin Turla (report)
- twitter.com — 944741575837528064 (report)
- Kaspersky — Penquins Moonlit Maze Pdf Eng (report)
- media.kasperskycontenthub.com — Penquins Moonlit Maze Pdf Eng (report)
- lab52.io — Looking For Penquins In The Wild (report)
- blackberry.com — Pdfviewer (report)
- leonardocompany.com — Malware+Technical+Insight+ Turla+%E2%80%9Cpenquin X64%E2%80%9D (report)
- youtube.com — Watch (report)
- Kaspersky — 97239 (report)
- Kaspersky — Penquins Moonlit Maze Appendixb (report)