Epic Backdoor
Epic is a backdoor created by the Turla advanced persistent threat group for use as a primary stage in their campaigns
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Epic is a backdoor created by the Turla advanced persistent threat group for use as a primary stage in their campaigns
Affected platforms
The following platforms are known to be affected:
Threat details
Turla use a variety of vectors to deliver Epic, including:
- Spear-phishing campaigns using Adobe PDF exploits.
- Watering hole attacks using Java, Flash or Internet Explorer exploits.
- Socially engineering users to install Epic or malicious scripts.
Once Epic is installed it will initiate communications with Turla's command and control infrastructure before transmitting system and user information to the group. They will then use that information to determine what malware to install on the device via Epic.
For further information
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:42 pm