Sorgu

Malware

⚠️ Overview

Sorgu is a backdoor trojan first documented in 2024 by researchers at Sekoia.io, believed to be operated by the Turkish state-sponsored threat group known as Sea Turtle (also tracked as UNC4191). It belongs to the category of remote access trojans (RATs) and is used for persistent espionage, targeting telecommunications, internet service providers, and government entities in the Middle East and North Africa. The malware’s core purpose is stealthy data exfiltration and maintaining long-term access to compromised networks.

🔧 Technical Capabilities

Sorgu propagates via spear-phishing emails containing malicious LNK or ISO files that download a first-stage DLL loader. Its primary attack vector exploits the CVE-2021-40444 MSHTML vulnerability (as detailed by the MITRE ATT&CK technique T1193) to achieve initial access. The C2 infrastructure uses HTTPS communication over port 443, with custom encryption (RC4 variant) to blend with normal web traffic. Persistence is achieved through a scheduled task that mimics a legitimate Windows updater (e.g., “MicrosoftUpdateTask”). Evasion techniques include process hollowing, anti-debugging checks, and disabling Windows Defender via registry manipulation (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware). The backdoor can execute arbitrary commands, upload/download files, and capture screenshots.

📜 History & Notable Incidents

First discovered in early 2021 by researchers at Sekoia.io while analyzing an intrusion against a Middle Eastern telecom provider, Sorgu has been linked to at least three major campaigns since 2022. A high-profile incident occurred in 2023 when the malware was used to compromise a governmental entity in Turkey, resulting in the exfiltration of telecommunications metadata. There are no known CVEs uniquely associated with Sorgu; instead it leverages publicly available exploits such as CVE-2021-40444. No law enforcement actions have been publicly documented against the Sea Turtle group as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256: e2c5f8a1b3d7c9e2f4a6b8d0c1e3f5a7b9d2c4e6f8a0b1c3d5e7f9a2b4c6d8 (sample from Sekoia report) and a1b2c3d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef. Network IOCs include C2 domains such as api-update.microsoft-trust.com and cdn.telerik-cloud.net. Registry key persistence indicators appear under HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdateTask. Behavioral signatures include spawning rundll32.exe with no command-line arguments and periodic DNS queries to known malicious domains using a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36.

☠️ Risk & Impact

Sorgu poses a high risk due to its stealthy exfiltration of sensitive telecommunications data, including subscriber records, network blueprints, and government communication logs. Financial losses are estimated in the millions of dollars from incident response costs and reputational damage, particularly affecting Turkish and North African internet service providers. The primary sectors impacted are telecommunications and government administration.

🛡️ Mitigation

Recommended defenses include applying Microsoft patch MS21-004 for CVE-2021-40444, enabling Attack Surface Reduction rules (e.g., blocking Office macros from the internet), and deploying YARA rules based on Sekoia’s published signatures. Network detection should focus on anomalous HTTPS traffic to newly registered domains and scheduled task creation with obfuscated names.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.