BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Turla’s Kazuar Malware Evolves Into Stealthy P2P Botnet

Turla evolves Kazuar malware into modular, resilient P2P espionage botnet.

  • The Russian state-sponsored group Turla (aka Secret Blizzard) has evolved its Kazuar malware into a modular, peer-to-peer botnet.
  • This new architecture features three specialized modules—Kernel, Bridge, and Worker—for coordinated, stealthy intelligence collection.
  • The botnet is designed for long-term persistence and targets government, diplomatic, and defense sectors in Europe and Central Asia.
  • Kazuar uses sophisticated communication methods and a centralized on-disk staging area to minimize direct contact with command servers.

In a significant escalation of cyber espionage capabilities, the Russian hacking group Turla has transformed its custom backdoor into a sophisticated peer-to-peer botnet, according to a report published by the Microsoft Threat Intelligence team. The group, affiliated with Russia’s FSB, continues to target government and defense sectors across Europe and Central Asia to support Kremlin objectives.

- Advertisement -

Microsoft’s analysis shows Kazuar’s evolution from a monolithic tool into a modular ecosystem engineered for resilience. This upgrade aligns with the group’s broader objective of gaining long-term access for intelligence collection.

Consequently, the new botnet architecture is built around three distinct component types. These include the Kernel module, which acts as the central coordinator and leader.

The Bridge module functions as a proxy between the leader and the command-and-control server. Meanwhile, the Worker module is responsible for logging keystrokes and gathering sensitive system information.

Attacks distributing this malware typically rely on droppers like Pelmeni and ShadowLoader. These tools decrypt and launch the modular components onto compromised systems.

- Advertisement -

The Kernel module uses an election process to designate a single leader for communication. “Once a leader is elected, it announces itself as the leader and tells all other Kernel modules to set SILENT,” Microsoft explained.

Data collected by the Worker is aggregated, encrypted, and staged in a dedicated working directory. From there, it is exfiltrated to the command servers controlled by the attackers.

Microsoft noted that “Kazuar uses a dedicated working directory as a centralized on-disk staging area to support its internal operations.” This design allows the malware to maintain operational state across system restarts.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Firm seeks $344M in frozen Tether tied to Iran

Gerstein Harrow LLP is seeking a court order to compel Tether to release over...

ChatGPT Can Now Access Your Bank Data via Plaid

OpenAI launched a ChatGPT personal finance feature with read-only access to users' bank data...

CME, ICE Seek Stricter Hyperliquid Oversight

Hyperliquid's HYPE token surged over 5% despite market-wide losses, buoyed by the launch of...

THORChain Exploited: $10M Loss, Trading Paused

THORChain, a cross-chain liquidity protocol, was likely exploited for an estimated $10 million in...

Analysts Warn Ether at Risk of 20% Drop to $1,700

Market analysts warn of downside risks for Ether (ETH), citing significant inflows onto exchanges...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading