Kazuar is a .NET-based backdoor associated with cyber-espionage activity and widely linked to the Turla threat actor. It is designed to provide remote operators with broad control over compromised systems, including command execution, file transfer, screenshot capture, webcam capture, process listing and termination, system information collection, and malware updating. The malware supports plugin-based extensibility, allowing operators to expand functionality after deployment.
Kazuar primarily targets Windows systems, where it has been observed using multiple persistence mechanisms, including Startup-folder shortcuts and Registry autorun locations. It can also install itself as a service. On Windows, it is capable of saving a DLL to disk and injecting it into explorer.exe, and it can be configured to inject into other processes as well. The malware performs host reconnaissance by gathering user information, network adapter details, and running process information, using WMI on Windows and native shell commands on Unix-like systems. It also supports file upload from victim directories and deletion of files on the host.
For command and control, Kazuar supports multiple protocols, including HTTP, HTTPS, FTP, and FTPS, and can be configured with multiple command-and-control URLs for resilience. Observed variants have used HTTP and Base64-encoded values in communications. A notable feature is a built-in webserver that exposes an API on the compromised host, enabling operators to submit tasks and retrieve results through inbound HTTP methods. The malware has also been associated with compromised web infrastructure used as command-and-control relays.
Code paths indicate cross-platform intent, with logic to distinguish Windows from Unix-like environments and command execution support for both. Kazuar has been described as a stealthy espionage backdoor and has been discussed as a possible successor or companion to other Turla backdoors such as Carbon and Gazer. It has also been reported in operations targeting government entities and Ukrainian defense-related organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turla uses HyperStack, Carbon, and Kazuar to compromise government entity.
Gamaredon used its library of loaders to provide initial access for Turla's heftier exploitation framework, Kazuar.
...на уражені ЕОМ довантажується складний багатофункціональний бекдор KAZUAR, в якому реалізовано більше 40 функцій...
...угрупуванням UAC-0028 (APT28) та UAC-0003 (Turla), зокрема, із застосуванням модифікованого флагманського шкідливого програмного забезпечення KAZUAR.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Kazuar’s ‘cmd’ command will run commands using “cmd.exe” for Windows systems and “/bin/bash” for Unix systems.
If the malware was executed with the "install" command-line argument, which uses .NET Framwork’s InstallHelper method to install the malware as a service. If the malware is started in a non-user interactive environment (no user interface), the malware installs itself as a service.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
If no arguments are provided and the malware determines it is running in a Windows environment, it saves a DLL to the system that it injects into the explorer.exe process.
If the malware was executed with the "install" command-line argument, which uses .NET Framwork’s InstallHelper method to install the malware as a service. If the malware is started in a non-user interactive environment (no user interface), the malware installs itself as a service.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
In April 2025, STOCKSTAY adopted a new string obfuscation method based on a pseudo-random algorithm called Squirrel3... GTIG tracks this as K1MORPHER.
Originally disguised as a stock market application, the malware has more recently masqueraded as legitimate software such as PDF readers and calculator programs.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Kazuar has the capabilities to use multiple protocols, such as HTTP, HTTPS, FTP or FTPS, determined by the prefixes of the hardcoded C2 URLs. So far, we have only observed HTTP used as the C2 protocol in our sample set.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
104 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware family associated with Turla that has continued to evolve and remained in use in 2026 for espionage activity.
A longer-running Turla espionage toolkit/backdoor that shares architectural and development similarities with STOCKSTAY, including multi-component design, environmental keying, and overlapping obfuscation code.
A known Turla implant referenced as sharing code and functionality overlap with StockStay.
A long-standing Turla implant/backdoor used since 2017. In this content it is described as architecturally similar to STOCKSTAY, with Kernel, Bridge, and Worker modules and multi-hop C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.