Briefing

Turla Transforms Kazuar Backdoor into Modular P2P Botnet for Stealth

security
by [email protected] (The Hacker News) ·

Turla has upgraded its Kazuar backdoor into a modular P2P botnet that provides stealthy, persistent access to compromised hosts.

What to do now

Monitor for signs of Turla’s P2P botnet activity and strengthen endpoint detection to mitigate stealthy intrusions.

Summary

The Russian state‑sponsored hacking group Turla, identified by the U.S. Cybersecurity and Infrastructure Security Agency as affiliated with the FSB’s Center 16, has upgraded its custom backdoor, Kazuar, into a modular peer‑to‑peer botnet. The new architecture allows the malware to operate stealthily and maintain persistent access to compromised hosts across a wide network.

Turla’s modular design enables the botnet to dynamically load additional modules, such as credential stealers or ransomware payloads, while keeping the core backdoor lightweight and difficult to detect. The group’s use of a P2P network reduces reliance on centralized command and control servers, further enhancing resilience against takedown efforts. Security researchers warn that the botnet’s stealth capabilities could make it a significant threat to enterprises and critical infrastructure.

Key changes

  • Turla transformed Kazuar backdoor into modular P2P botnet.
  • Modular design allows dynamic loading of modules (credential stealers, ransomware).
  • P2P architecture reduces reliance on centralized C2 servers.
  • Botnet provides stealthy, persistent access to compromised hosts.
  • CISA identified Turla as affiliated with FSB Center 16.

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting