Turla APT Using KopiLuwak Malware
Turla, Advanced Persistent Threat (APT) group, is responsible for sending out malicious attachments sent to invite recipients to the G20 task force meeting on the Digital Economy.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Turla, Advanced Persistent Threat (APT) group, is responsible for sending out malicious attachments sent to invite recipients to the G20 task force meeting on the Digital Economy.
Affected platforms
The following platforms are known to be affected:
Threat details
Spread via email, a MSIL dropper is used with a decoy PDF (named “Save the Date G20 Digital Economy Taskforce 23 24 October.pdf”). Once opened KopiLuwak is installed, the victims machine is profiled, persistence is established and backdoor functionality is installed.
KopiLuwak itself is capable of data exfiltration, executing arbitrary commands, and downloading further payloads.
Remediation steps
Last edited: 17 February 2020 11:40 am