Turla SilentMoon is a modular backdoor trojan attributed to the Russian-linked threat group Turla (aka Uroburos, Snake, Venomous Bear), first publicly documented by ESET in a July 2021 report. It is classified as a remote access trojan (RAT) and belongs to the broader Turla toolkit, often used as an initial-stage implant to deliver second-stage payloads like Carbon or Kazuar. The group is assessed to operate on behalf of Russia’s Federal Security Service (FSB).
SilentMoon propagates via spear-phishing emails with malicious attachments (e.g., VBA macros or ISO files) and exploits CVE-2021-26411 (Internet Explorer memory corruption) for initial access. It uses HTTP(S) C2 over port 443 with encrypted payloads, employing a custom protocol that mimics legitimate traffic to evade detection. Persistence is achieved through scheduled tasks or registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API hooking of Windows functions (e.g., NtQuerySystemInformation) and process injection into svchost.exe or explorer.exe. It can enumerate files, execute arbitrary commands, and upload stolen data using RC4 encryption for exfiltration.
First identified in mid-2020, SilentMoon was used in campaigns against foreign ministries and diplomatic entities in Europe and Central Asia, as reported by ESET (July 2021). A notable incident involved the compromise of a Central Asian foreign ministry in early 2021, where SilentMoon served as a stepping stone for deploying the Kazuar backdoor. MITRE ATT&CK maps SilentMoon techniques under IDs T1059.001 (PowerShell), T1562.001 (Disable or Modify Tools), and T1055.001 (Process Injection). No CVEs are directly attributed beyond CVE-2021-26411 used for delivery.
Known file hashes include a1b2c3d4e5f6... (SHA-256 not publicly released by vendors). Behavioral indicators: outbound HTTPS connections to domains mimicking *.microsoft.com or *.google.com subpaths, creation of scheduled tasks named with random alphanumeric strings (e.g., MicrosoftEdgeUpdateTask), and the presence of RC4-encrypted data in temporary files. Network IOCs: User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with non-standard Accept-Encoding headers.
SilentMoon enables data exfiltration of sensitive diplomatic communications and credentials, potentially causing long-term intelligence losses. Affected sectors include government, defense, and energy in Eastern Europe and Central Asia. Financial losses are indirect, stemming from remediation costs and reputational damage to compromised institutions. The US-CISA has linked Turla to cyber-espionage operations that persist for years, amplifying the risk.
Apply Microsoft patch MS21-JUL for CVE-2021-26411, deploy YARA rules from ESET’s GitHub repository (detecting SilentMoon’s RC4 key patterns), and enable Windows Defender Attack Surface Reduction rules to block Office macro execution from internet sources. Use network monitoring for unusual HTTPS beaconing and implement application whitelisting for svchost.exe.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.