Russian Hackers Hijack Their Way to Starlink: Turla’s Latest Cyber Shenanigans in Ukraine

Russian cyber-espionage group Turla, aka Secret Blizzard, is causing chaos by hijacking other hackers’ systems to target Ukrainian military devices. By piggybacking on the Amadey botnet and Storm-1837, Turla deploys its custom malware, Tavdig and KazuarV2, to gather intelligence. It’s a classic case of hackers hacking hackers.

Pro Dashboard

Hot Take:

Turla, the cyber equivalent of a sneaky cat burglar, is once again up to its old tricks! Instead of breaking into just any house, they’ve chosen to hide inside other crooks’ hideouts. With their latest escapade targeting Ukrainian military devices via Starlink, it’s clear Turla is determined to keep its cyber-espionage game as unpredictable as a Russian nesting doll. Bravo, you scoundrels!

Key Points:

  • Turla is leveraging other cybercriminal groups’ infrastructures to target Ukrainian military devices using Starlink.
  • The campaign utilizes the Amadey botnet and Storm-1837’s infrastructure for malware deployment.
  • Turla’s custom malware families, Tavdig and KazuarV2, are used for espionage purposes.
  • Microsoft is uncertain if Turla hijacked the Amadey botnet or accessed it through other means.
  • The attacks align with Turla’s association with Russia’s Federal Security Service (FSB).

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?