Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Turla operation targeting Ukrainian systems began in December 2021 and was discovered in September 2022, according to a January 6, 2023 CyberScoop report on Mandiant’s findings. The report described a way to hijack another malware campaign’s infrastructure—not a newly confirmed 2026 attack. It did not identify the Ukrainian organizations affected or quantify the operation’s impact.

What happened in the reported Turla operation?

CyberScoop reported that an infected USB stick was inserted into a Ukrainian system in December 2021. The stick carried a 2013 version of Andromeda malware. That malware sent beacons to command-and-control infrastructure associated with Turla, allowing the group to exploit an existing infection rather than distribute its own USB malware.

According to the report, Turla appeared to reuse infrastructure from an earlier, likely criminal campaign. That included expired domains the group had re-registered. The reporting does not establish who originally operated that campaign or precisely how the access was obtained.

What tools did the report identify?

Mandiant’s findings, as described by CyberScoop, named two tools used in the operation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Kopiluwak: a reconnaissance utility.
  • Quietcanary: a backdoor.

The tools were downloaded multiple times in succession. Mandiant suggested this could reflect haste, less concern about operational security, an operational deficiency, or automated tooling; the report did not establish which explanation was correct.

What was Turla trying to learn?

The report says victim profiling began in January, but does not specify the year in that description. Mandiant characterized the work as “extensive profiling,” intended to let the group select particular systems and tailor follow-on exploitation to gather information of strategic importance. The reporting does not name the Ukrainian entities targeted, identify specific information obtained, or quantify any consequences.

Why did the operation stand out?

John Hultquist, Mandiant’s head of threat intelligence, said the “new spin” was that the actors were not releasing their own USB malware into the wild. Instead, he said, Turla was taking advantage of another actor’s work by taking over its command-and-control infrastructure. In his account, this approach let Turla avoid the more visible work of spreading malware while retaining the ability to select victims of interest.

That distinction matters: the reported approach involved leveraging an existing infection and infrastructure, not a documented mass campaign of newly distributed USB devices. CyberScoop described Turla as linked to Russia’s Federal Security Service (FSB); that characterization is the article’s attribution, not an independent assessment here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is this evidence of a current Turla resurgence?

No. The operation described began in December 2021, was discovered in September 2022, and was covered by CyberScoop on January 6, 2023. Those dates do not establish that Turla launched a fresh campaign in 2026. Hultquist described the difficulty of tracking the group this way: “We get glances of them and then they disappear on us.”

Turla is also distinct from Gamaredon, another group covered in separate reporting about activity against Ukrainian organizations. Details attributed to Gamaredon—including LNK files and script-based malware—are not part of this Turla incident and should not be conflated with it.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.