Zum Hauptinhalt springen
Unix & Linux ServerDistribution Release: Qubes OS 4.3.2(03.10.2026 um 00:03 Uhr)
•
Linux Tipps & HardeningSecurity: Mehrere Probleme in redis (Debian)(03.10.2026 um 01:01 Uhr)
•
Sichere ProgrammierungCopilot code review: API support and new default effort level(02.10.2026 um 21:13 Uhr)
•
Sichere ProgrammierungStateless GitHub App installation tokens rolled out(03.10.2026 um 00:18 Uhr)
•
Sichere ProgrammierungWe Tried ISO-AdamW. AdamW Kept Its Job.(03.10.2026 um 00:08 Uhr)
•
Sichere ProgrammierungClaim Ledger gives a project review a paper trail(03.10.2026 um 00:10 Uhr)
••
Sichere ProgrammierungWhat getting into thirteen database projects' docs actually took(03.10.2026 um 00:11 Uhr)
•
Sichere ProgrammierungYour security gate always passes. Can it actually block a release?(03.10.2026 um 00:11 Uhr)
•
Sichere Programmierung🚀 Starting my Hacktoberfest journey!(03.10.2026 um 00:12 Uhr)
•
Unix & Linux ServerDistribution Release: Qubes OS 4.3.2(03.10.2026 um 00:03 Uhr)
•
Linux Tipps & HardeningSecurity: Mehrere Probleme in redis (Debian)(03.10.2026 um 01:01 Uhr)
•
Sichere ProgrammierungCopilot code review: API support and new default effort level(02.10.2026 um 21:13 Uhr)
•
Sichere ProgrammierungStateless GitHub App installation tokens rolled out(03.10.2026 um 00:18 Uhr)
•
Sichere ProgrammierungWe Tried ISO-AdamW. AdamW Kept Its Job.(03.10.2026 um 00:08 Uhr)
•
Sichere ProgrammierungClaim Ledger gives a project review a paper trail(03.10.2026 um 00:10 Uhr)
••
Sichere ProgrammierungWhat getting into thirteen database projects' docs actually took(03.10.2026 um 00:11 Uhr)
•
Sichere ProgrammierungYour security gate always passes. Can it actually block a release?(03.10.2026 um 00:11 Uhr)
•
Sichere Programmierung🚀 Starting my Hacktoberfest journey!(03.10.2026 um 00:12 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Turla Hacker Group Steals Antivirus Logs To See If Its Malware Was Detected

An anonymous reader quotes a report from ZDNet: Security researchers from ESET have discovered new attacks carried out by Turla, one of Russia's most advanced…

Beitrag
0
Seite
0
↗ Quelle (it.slashdot.org)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!
An anonymous reader quotes a report from ZDNet: Security researchers from ESET have discovered new attacks carried out by Turla, one of Russia's most advanced state-sponsored hacking groups. The new attacks have taken place in January 2020. ESET researchers say the attacks targeted three high-profile entities, such as a national parliament in the Caucasus and two Ministries of Foreign Affairs in Eastern Europe. Targets could not be identified by name due to national security reasons. [...] The ComRAT malware, also known as Agent.BTZ, is one of Turla's oldest weapons, and the one they used to siphon data from the Pentagon's network in 2008. The tool has seen several updates across the years, with new versions discovered in 2014 and 2017, respectively.

The latest version, known as ComRAT v4, was first seen in 2017, however, in a report published today, ESET says they've spotted a variation of ComRAT v4 that includes two new features, such as the ability to exfiltrate antivirus logs and the ability to control the malware using a Gmail inbox. The first of these features is the malware's ability to collect antivirus logs from an infected host and upload it to one of its command and control servers. The exact motives of a hacker group will always remain unclear, but Matthieu Faou, the ESET researcher who analyzed the malware, told ZDNet that Turla operators might be collecting antivirus logs to "allow them to better understand if and which one of their malware sample was detected." The belief is that if Turla operators see a detection, they can then tweak their malware and avoid future detections on other systems, where they can then operate undetected.

Read more of this story at Slashdot.

🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
1 belegte Technik
T1071TA0011 · Command and Control
Application Layer Protocol (C2)
Mitigation: M1031 Network Intrusion Prevention & Egress Filtering
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
3 Knoten · 2 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Turla Hacker Group Steals Antivirus Logs To See If Its Malware Was Detected

Thematisch verwandte Begriffe: Turla, Hacker, Group, Steals · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag