{"id":246903,"date":"2026-05-15T13:10:00","date_gmt":"2026-05-15T17:10:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/15\/turla-turns-kazuar-backdoor-into-modular-p2p-botnet-for-persistent-access\/"},"modified":"2026-05-15T18:35:07","modified_gmt":"2026-05-15T22:35:07","slug":"turla-turns-kazuar-backdoor-into-modular-p2p-botnet-for-persistent-access","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/15\/turla-turns-kazuar-backdoor-into-modular-p2p-botnet-for-persistent-access\/","title":{"rendered":"Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/turla-turns-kazuar-backdoor-into.html\">Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/turla-turns-kazuar-backdoor-into.html\">https:\/\/thehackernews.com\/2026\/05\/turla-turns-kazuar-backdoor-into.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-15 13:10:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">May 15, 2026<\/span><\/span><span class=\"p-tags\">Botnet \/ Threat Intelligence<\/span><\/p>\n<p>\n  The Russian state-sponsored hacking group known as<\/p>\n<p>    Turla<\/p>\n<p>  has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that&#8217;s engineered for stealth and persistent access to compromised hosts.\n<\/p>\n<p>\n  Turla, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA), is assessed to be affiliated with Center 16 of Russia&#8217;s Federal Security Service (FSB). It overlaps with activity traced by the broader cybersecurity community under the names ATG26, Blue Python, Iron Hunter, Pensive Ursa, Secret Blizzard (formerly Krypton), Snake, SUMMIT, Uroburos, Venomous Bear, Waterbug, and WRAITH.\n<\/p>\n<p>\n  The hacking group is known for its attacks targeting government, diplomatic, and defense sectors in Europe and Central Asia, as well as<br \/>\n  endpoints previously breached by Aqua Blizzard<br \/>\n  (aka Actinium and Gamaredon) to support the Kremlin&#8217;s strategic objectives.\n<\/p>\n<p>\n  &#8220;This upgrade aligns with Secret Blizzard&#8217;s broader objective of gaining long-term access to systems for intelligence collection,&#8221; the Microsoft Threat Intelligence team<br \/>\n  said<br \/>\n  in a report published Thursday. &#8220;While many threat actors rely on increasing usage of native tools (living-off-the-land binaries (LOLBins)) to avoid detection, Kazuar&#8217;s progression into a modular bot highlights how Secret Blizzard is engineering resilience and stealth directly into their tooling.&#8221;\n<\/p>\n<p>\n  A key tool in Turla&#8217;s arsenal is<br \/>\n  Kazuar<br \/>\n  , a<br \/>\n  sophisticated .NET backdoor<br \/>\n  that has been consistently put to use since 2017. The latest findings from Microsoft charts its evolution from a &#8220;monolithic&#8221; framework into a modular bot ecosystem featuring three distinct component types, each with its own well-defined roles. These changes enable flexible configuration, reduce observable footprint, and facilitate broad tasking.\n<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tr>\n<td style=\"text-align: center;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"815\" data-original-width=\"1200\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi58cEcaYYTALrjjxOzEDzah6YL_6w8HwTluSdahy2WR1zczaIh38gTTuC5atacFNUnvEkZ1w4b_inDCoeO9QB6h4hDUgXZImhSmGK0q_BzW0M1yEJPcql-BoBkk9xd6ssx4R_iYxGN5eUGZ-49rFGtdxGTMrV3i8FpVB3XB5SmgoQYz1IUjitKRGUczVIG\/s1600\/command.jpg\"\/><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Overview of Kernel, Bridge, and Worker module interactions<\/td>\n<\/tr>\n<\/table>\n<p>\n  Attacks distributing the malware have been found to&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/turla-turns-kazuar-backdoor-into.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access https:\/\/thehackernews.com\/2026\/05\/turla-turns-kazuar-backdoor-into.html Publish Date: 2026-05-15&#8230;<\/p>\n","protected":false},"author":1,"featured_media":246904,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg8BT1AOScncZQM_A-0WBdCzTDAHGHSey48_Mywhij-TJupCdzP3s3o-MIImRtMZcoV2OqX3RjRV4COpVqkB1mrH3d_zjwvSTwCEXOq_2m80HgDo-xwAZ1KpR1h8eN9dAHGcKN_PpcE0cBsnv67FcthDycHLBJMYs8NkPszWNiQqdbhyL0YIlwVJn4NtgaR\/s1600\/code.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,32],"class_list":["post-246903","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246903"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=246903"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246903\/revisions"}],"predecessor-version":[{"id":246905,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/246903\/revisions\/246905"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/246904"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=246903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=246903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=246903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}