Skip to main content

Turla APT Using KopiLuwak Malware

Turla, Advanced Persistent Threat (APT) group, is responsible for sending out malicious attachments sent to invite recipients to the G20 task force meeting on the Digital Economy.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Turla, Advanced Persistent Threat (APT) group, is responsible for sending out malicious attachments sent to invite recipients to the G20 task force meeting on the Digital Economy.

Affected platforms

The following platforms are known to be affected:

Threat details

Spread via email, a MSIL dropper is used with a decoy PDF (named “Save the Date G20 Digital Economy Taskforce 23 24 October.pdf”). Once opened KopiLuwak is installed, the victims machine is profiled, persistence is established and backdoor functionality is installed.

KopiLuwak itself is capable of data exfiltration, executing arbitrary commands, and downloading further payloads.


Remediation steps

Type Step
  • If your network becomes infected immediately report it to your AV provider for investigation and patching
  • Educate staff on the dangers associated with malicious emails and spear-phishing campaigns; staff should be vigilant and ensure they do not click on links or open attachments from unsolicited emails or override security controls such as "enable editing"
  • Keep all anti-virus software up-to-date including the latest signatures
  • User accounts accessed from infected machines should be reset on a clean computer

Last edited: 17 February 2020 11:40 am