Briefing

Turla Enhances Kazuar Backdoor into Stealthy P2P Botnet

security
by Bill Toulas ·

Deploy behavioral detection for Kazuar’s modular P2P botnet to identify and block its stealthy C2 traffic.

What to do now

Deploy behavioral detection for Kazuar’s modular P2P botnet to identify and block its stealthy C2 traffic.

Summary

Russian state‑sponsored hacking group Turla has upgraded its custom backdoor, Kazuar, into a modular peer‑to‑peer (P2P) botnet that offers long‑term persistence and stealthy data exfiltration. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Turla is linked to Center 16 of Russia’s Federal Security Service (FSB). The new architecture eliminates a central command server, making the botnet harder to detect and dismantle. Kazuar’s modular design allows attackers to load additional payloads on the fly, extending its capabilities across compromised hosts.

The botnet’s P2P network enables infected machines to communicate directly with one another, creating a resilient web of compromised devices that can survive the takedown of individual nodes. Encryption and anti‑analysis techniques further obscure traffic, while dynamic payload loading keeps defenders guessing about the botnet’s true purpose. Security teams are advised to monitor for unusual P2P traffic patterns that match Kazuar’s signature, as the botnet’s stealth features make it a persistent threat to corporate and government networks alike.

Turla’s evolution of Kazuar reflects a broader trend among Russian cyber actors to develop more sophisticated, distributed infrastructures that reduce single points of failure. By shifting from a traditional backdoor to a modular P2P botnet, Turla can maintain covert access to targets for extended periods, quietly exfiltrating data while evading conventional detection methods. The upgrade underscores the importance of proactive monitoring and threat intelligence sharing to counter state‑sponsored cyber espionage.

Key changes

  • Kazuar now consists of kernel, bridge, and worker modules.
  • Kernel module coordinates tasks and elects a leader.
  • Bridge module proxies external C2 via HTTP, WebSockets, or EWS.
  • Worker module performs keylogging, screenshots, and data exfiltration.
  • Communications use AES encryption and Protocol Buffers.
  • Supports 150 configuration options, including AMSI, ETW, and WLDP bypasses.
  • Collects cloud provider tokens, SSH keys, and local keychain files.
  • Microsoft recommends behavioral detection over static signatures.

Affects

enterprise

Source angles · 2 perspectives

Bleeping Computer
Independent angle

Russian hackers turn Kazuar backdoor into modular P2P botnet

Open
The Hacker News
Independent angle

Turla Evolves Kazuar Backdoor into Modular P2P Botnet for Stealth Access

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting