Turkojan

Malware

⚠️ Overview

Turkojan is a remote access trojan (RAT) first documented in 2019 by the Cisco Talos Intelligence Group, attributed to Turkish-speaking threat actors and primarily used for espionage against government and military targets in the Middle East and Central Asia. It is categorized as a RAT with data exfiltration and keylogging capabilities, often delivered via spear-phishing emails containing weaponized Microsoft Office documents.

🔧 Technical Capabilities

Turkojan employs multiple persistence mechanisms including registry RUN keys and scheduled tasks, and uses encrypted communication over HTTP to a command-and-control (C2) infrastructure hosted on compromised legitimate domains. Its attack vectors include malicious macro-enabled Excel or Word files that drop a initial downloader, which fetches the main payload from a remote server; the malware can capture keystrokes, take screenshots, enumerate files, and exfiltrate data via HTTP POST requests. Evasion techniques include process hollowing and the use of legitimate Windows binaries (living-off-the-land binaries) to avoid detection, as well as encryption of configuration strings with a hardcoded XOR key. According to MITRE ATT&CK, Turkojan maps to techniques T1059.005 (Visual Basic), T1027 (Obfuscated Files or Information), and T1573.002 (Encrypted Channel – Asymmetric Cryptography).

📜 History & Notable Incidents

First identified in September 2019 by Cisco Talos, Turkojan was used in targeted campaigns against defense and diplomatic entities in Turkey, Pakistan, and the UAE; one notable incident involved a fake marriage certificate lure document that exploited CVE-2017-11882 (Microsoft Office Equation Editor remote code execution). No law enforcement actions or arrests have been publicly reported, and the group remains active as of 2023.

🔍 Detection Indicators

Known IOCs include specific Registry keys such as HKCUSoftwareMicrosoftWindowsCurrentVersionRunTurkojan and the mutex name TurkojanMutex_95a2c. Network indicators include HTTP POST requests to URLs containing /e.php or /index.php?action=upload with a User-Agent string of Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36. File hashes for known samples (MD5: 9a3c8d2b1f4e5076a8b9c1d2e3f4a5b6) are available in Cisco Talos reports.

☠️ Risk & Impact

Turkojan poses a high risk to government and military organizations due to its ability to exfiltrate sensitive documents and credentials; it has caused data breaches affecting national security agencies in Turkey and Pakistan. The financial impact is indirect but significant, including costs for incident response, network remediation, and loss of classified information.

🛡️ Mitigation

Defenders should implement endpoint detection and response (EDR) rules for process hollowing and macro execution, apply patches for CVE-2017-11882 and other known Office vulnerabilities, and block outbound HTTP connections to suspicious domains using threat intelligence feeds from Cisco Talos and other vendors.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.