Carbon, also known as Project Cobra, is a modular Windows backdoor framework attributed to the Turla espionage group. It has been used as a second-stage implant in long-term intrusions against high-value government and diplomatic targets, including foreign affairs ministries and embassies. Carbon is designed for stealthy post-compromise access and information theft, and has been associated with broader Turla operations that also employed implants such as HyperStack, Kazuar, and Gazer.
Carbon supports a range of post-exploitation functions including process discovery, process injection, Windows Registry enumeration, local network configuration discovery, remote system discovery, and system time discovery. Reported behavior includes listing running processes, injecting code into other processes, enumerating Registry values, collecting host and nearby network information, and querying local time. It also decrypts tasking and configuration data for execution, indicating an internal encrypted tasking architecture.
For persistence, Carbon has been observed creating scheduled tasks and installing itself as a Windows service, with service naming adapted to the operating system version. It also creates local working directories used to store collected files and operational data. Carbon has been described as modular and has been deployed with multiple components, including orchestration and communications modules.
Turla has used Carbon with advanced command-and-control tradecraft, including encrypted communications and flexible infrastructure. Public reporting has noted RSA-protected command-and-control data and use of CAST-128 in related Turla tooling. Carbon has also been observed using compromised web infrastructure and alternate tasking channels to maintain resilient access during government-focused espionage operations.
Carbon is best characterized as a sophisticated Turla backdoor used for covert persistence, reconnaissance, and data theft in targeted intrusions against state, diplomatic, and other high-value organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turla uses HyperStack, Carbon, and Kazuar to compromise government entity.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.
"Carbon uses the netstat -r and netstat -an commands."
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
It's a sophisticated backdoor used to steal sensitive information from high valuable targets like diplomats or foreign affairs ministries.
MITRE ATT&CK techniques ... Command and Control ... T1001 Data Obfuscation ... When accessing the Pastebin URL, an encrypted blob is downloaded that requires a corresponding RSA private key from the configuration file.
the Carbon instance had been updated to include a Pastebin project to receive encrypted tasks alongside its traditional HTTP C&C infrastructure. | Accenture researchers recently identified novel command and control (C&C) configurations for Turla’s Carbon and Kazuar backdoors on the same victim network.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
MITRE ATT&CK techniques ... Command and Control ... T1090 Proxy ... The October sample likely acts as a transfer agent used to proxy commands from the remote Turla operators to the Kazuar instances on internal nodes in the network via an internet-facing shared network location.
MITRE ATT&CK techniques ... Command and Control T1102 ... Web Service ... Turla has relied on traditional C&C implementations, using compromised web servers as C&C, as well as utilizing legitimate web services like Pastebin.
To compromise the organization's network, the attackers used a combination of recently updated remote administration trojans (RATs) and remote procedure call (RPC)-based backdoors including HyperStack
the attackers used a combination of recently updated remote administration trojans (RATs) and remote procedure call (RPC)-based backdoors
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Examples include: "encrypts some C2 with RSA", "RSA encryption for C2 communications", "hard-coded RSA public key", "RSA-2048", "RSA-4096", and "REvil has encrypted C2 communications with the ECIES algorithm". | Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collects victim and network host IP information using Windows networking commands.
Malware that decrypts tasking and configuration files for execution.
Backdoor malware that uses the net time command to discover system time.
Malware that supports code injection into processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.