Turla Mail Client Backdoor
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The backdoor is a self-contained DLL file that is able to install and operate itself on the targeted client. As such, it can be delivered by several Turla tools or by any other malware that is able to execute additional processes.
Once installed, the tool is able to intercept all email traffic, including metadata, from the affected client. It can also to execute commands and programs, exfiltrate data and download additional malware. The tool communicates with its command and control infrastructure using encoded emails, with new files being delivered as PDF attachments. These emails are kept hidden to prevent detection by the user.
For further information
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:55 pm