Attor is a highly modular, stealthy espionage platform first publicly documented in October 2020 by ESET researchers. It is attributed to the Russian-speaking advanced persistent threat group Turla (aka Snake, Venomous Bear, and Uroburos). Attor is categorized as a spyware backdoor and data exfiltration tool, designed for long-term surveillance operations against government and diplomatic targets.
Attor employs a unique three‑stage architecture: a initial dropper (often delivered via spear‑phishing emails with malicious documents), a core loader (module loader), and multiple encrypted plugins loaded from a custom encrypted filesystem (using AES‑256). The malware uses Tor for command‑and‑control (C2) communication, routing traffic through the Tor network and leveraging SOCKS proxies to hide its infrastructure. Persistence is achieved via scheduled tasks or Windows services. Evasion techniques include anti‑debugging, anti‑VM checks, and encrypting all plugin code and configuration data using a derived key from the victim’s machine fingerprint. The platform supports keylogging, screen capture, file exfiltration, and microphone/audio recording. C2 domains have been observed using dynamic DNS services (e.g., No‑IP) and legitimate cloud providers to blend with normal traffic. MITRE ATT&CK IDs associated include T1071 (Application Layer Protocol), T1573 (Encrypted Channel), and T1055 (Process Injection).
ESET’s 2020 report tied Attor to campaigns targeting embassies and consulates of multiple countries, including those of Kazakhstan, Kyrgyzstan, Tajikistan, and Eastern European nations. The malware was first seen in the wild as early as 2015, with active operations continuing into 2020. No specific CVEs are exploited; instead, it relies on social engineering to deliver initial payloads. No law enforcement actions have been publicly attributed to Attor operations.
ESET provides several indicators: file hashes for the loader and plugins (e.g., MD5: 0x2A1E…), registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun using obfuscated values, and the use of a custom user‑agent string in HTTP requests (Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0)). Network IOCs include specific Tor‑exit node IP addresses and domains such as mail.anexample[.]com. The mutex name GlobalD1E2F3 (variant‑dependent) has been observed. Behavioural signs include high outbound Tor traffic from a non‑Tor‑enabled workstation and encrypted files with the extension .att in temporary directories.
Attor’s primary impact is intelligence theft: it exfiltrates sensitive diplomatic communications, credentials, and internal documents. The affected sectors are overwhelmingly government, diplomatic missions, and military attaché offices. Since operations are stealthy and targeted, financial losses are indirect but severe—compromised negotiations, espionage‑driven policy manipulation, and loss of sovereign intellectual property.
Defenders should deploy endpoint detection and response (EDR) rules that monitor for Tor processes (e.g., tor.exe) on non‑authorized systems, block outbound connections to known Tor‑exit nodes via reputation lists, and enforce strict email attachment screening. ESET’s public report (https://www.welivesecurity.com/2020/10/22/attor-espionage-platform/) provides YARA rules and detailed IoCs for detection.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.