Kazuar is a modular, Microsoft .NET-based remote access trojan associated with Turla, a Russian state-sponsored cyberespionage group. It has been used in intrusions against government entities alongside other Turla malware, including Carbon and HyperStack. Gamaredon-associated PteroOdd and PteroPaste malware have also deployed Kazuar.
Kazuar provides remote command execution, file discovery and manipulation, uploads and downloads, screenshot and webcam capture, process enumeration and termination, and plugin installation and removal. It gathers system, user, and network-adapter information and can upload files from operator-specified directories to its command-and-control infrastructure. Its plugin and upgrade functions allow operators to extend or update functionality after deployment.
On Windows, Kazuar can write a DLL to disk and inject it into Windows Explorer or other configured processes. It supports persistence through registry autostart mechanisms, Startup-folder shortcuts, and service installation under specific launch conditions. Command-and-control uses HTTP, supports multiple server addresses, and includes Base64-encoded communications. Server responses can deliver XML tasks, and Kazuar can alternatively listen for inbound HTTP requests containing commands. Compromised legitimate websites have served as its command-and-control infrastructure. Windows is its confirmed target platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turla uses HyperStack, Carbon, and Kazuar to compromise government entity.
Gamaredon used its library of loaders to provide initial access for Turla's heftier exploitation framework, Kazuar.
...на уражені ЕОМ довантажується складний багатофункціональний бекдор KAZUAR, в якому реалізовано більше 40 функцій...
...угрупуванням UAC-0028 (APT28) та UAC-0003 (Turla), зокрема, із застосуванням модифікованого флагманського шкідливого програмного забезпечення KAZUAR.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
109 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor attributed in cited reporting to Turla; referenced only as a comparative example of cross-group malware deployment.
Custom malware family associated with Turla that has continued to evolve and remained in use in 2026 for espionage activity.
A longer-running Turla espionage toolkit/backdoor that shares architectural and development similarities with STOCKSTAY, including multi-component design, environmental keying, and overlapping obfuscation code.
A known Turla implant referenced as sharing code and functionality overlap with StockStay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.