BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Turla’s Kazuar Malware Evolves Into Stealthy P2P Botnet

Turla evolves Kazuar malware into modular, resilient P2P espionage botnet.

  • The Russian state-sponsored group Turla (aka Secret Blizzard) has evolved its Kazuar malware into a modular, peer-to-peer botnet.
  • This new architecture features three specialized modules—Kernel, Bridge, and Worker—for coordinated, stealthy intelligence collection.
  • The botnet is designed for long-term persistence and targets government, diplomatic, and defense sectors in Europe and Central Asia.
  • Kazuar uses sophisticated communication methods and a centralized on-disk staging area to minimize direct contact with command servers.

In a significant escalation of cyber espionage capabilities, the Russian hacking group Turla has transformed its custom backdoor into a sophisticated peer-to-peer botnet, according to a report published by the Microsoft Threat Intelligence team. The group, affiliated with Russia’s FSB, continues to target government and defense sectors across Europe and Central Asia to support Kremlin objectives.

- Advertisement -

Microsoft’s analysis shows Kazuar’s evolution from a monolithic tool into a modular ecosystem engineered for resilience. This upgrade aligns with the group’s broader objective of gaining long-term access for intelligence collection.

Consequently, the new botnet architecture is built around three distinct component types. These include the Kernel module, which acts as the central coordinator and leader.

The Bridge module functions as a proxy between the leader and the command-and-control server. Meanwhile, the Worker module is responsible for logging keystrokes and gathering sensitive system information.

Attacks distributing this malware typically rely on droppers like Pelmeni and ShadowLoader. These tools decrypt and launch the modular components onto compromised systems.

- Advertisement -

The Kernel module uses an election process to designate a single leader for communication. “Once a leader is elected, it announces itself as the leader and tells all other Kernel modules to set SILENT,” Microsoft explained.

Data collected by the Worker is aggregated, encrypted, and staged in a dedicated working directory. From there, it is exfiltrated to the command servers controlled by the attackers.

Microsoft noted that “Kazuar uses a dedicated working directory as a centralized on-disk staging area to support its internal operations.” This design allows the malware to maintain operational state across system restarts.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Panel: Bitcoin Could Crash to $30K or Soar to $130K

Patrick Bet-David suggested Bitcoin's price could swing dramatically, falling to $30,000 or surging to...

Bitcoin Plunges Amid Selloff; All Eyes on Saylor’s Next Move

Bitcoin plunged over 50% from its October 2025 peak of $126,000, wiping $2 trillion...

Broadcom Earnings Spark Semiconductor Stock Plunge

Broadcom's Q2 earnings, which beat expectations, triggered a 12.6% crash in its own stock...

Microsoft Found Vulnerability in Anthropic’s Claude Code

Microsoft researchers discovered a Claude Code vulnerability where attack instructions in GitHub comments could...

OpenAI Launches ChatGPT ‘Lockdown Mode’ to Block Data Leaks

OpenAI has launched a new optional Lockdown Mode for ChatGPT personal accounts to mitigate...

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading