Russian-Speaking APTs Turla and Sofacy Share Malware Delivery Scheme, Select Targets in Asia
Summary
The researchers also found target overlap between the two threat actors, centered on geopolitical hotspots in central Asia, as well as sensitive government and military entities.In their overview, the researchers provide further evidence to support the hypothesis that Wi-Fi networks were abused by Turla to deliver Mosquito malware to victims, a practice that may be tapering off.The 2018 targets for the Turla malware clusters include the Middle East and Northern Africa, as well as parts of Western and Eastern Europe, Central and South Asia and the Americas.“Turla is one of the oldest, most enduring and capable known threat actors, renowned for constantly shedding its skin and trying out new innovations and approaches,” said Kurt Baumgartner, principal security researcher, Kaspersky Lab GReAT.However, it is worth noting that while other Russia-speaking threat actors like CozyDuke (APT29) and Sofacy were targeting organizations in the west, such as allegedly hacking the Democratic National Committee in 2016, Turla was quietly deploying its operations towards the east, where their activity and, more recently, even their delivery techniques began to overlap with Sofacy’s Zebrocy subset.