LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0668: TinyTurla

TinyTurla is a backdoor that has been used by Turla against targets in the US, Germany, and Afghanistan since at least 2020.[1]

EnterpriseS0668MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

TinyTurla matters because ATT&CK describes it as a Windows backdoor associated through MITRE relationships with Turla and with behaviors that support persistence, stealth, command-and-control, tool transfer, local data collection, and scheduled exfiltration. For leaders, the decision value is not the malware name alone; it is whether Windows endpoint, registry, service, command-shell, and web-traffic monitoring can show what changed, what communicated externally, and whether sensitive data staging or transfer occurred.

Executive priority

Prioritize TinyTurla as an assessment point for Windows backdoor readiness: endpoint visibility, service and registry change control, outbound web traffic governance, and incident response evidence retention. The ATT&CK relationship to Turla raises threat-intelligence relevance for organizations that track espionage-oriented intrusion risk, but local exposure and impact must be determined from environment telemetry, not assumed from the ATT&CK entry.

Technical view

Validate coverage around the related ATT&CK behaviors: Windows Command Shell and Native API execution; Service Execution and masqueraded task/service names; Registry query, modification, and fileless storage; web-protocol command-and-control with fallback channels and asymmetric cryptography; ingress tool transfer; local system data collection; and scheduled transfer. Because MITRE provides no official detection text for S0668, SOC teams should map detections to the related techniques rather than relying on a TinyTurla-specific analytic alone.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry, especially cmd.exe and service-control activity
  • Windows service creation, modification, execution, display name, and binary path records
  • Windows Registry query and modification telemetry, including unusual persistence or storage locations
  • Endpoint file, memory, and configuration evidence related to local data discovery or staging
  • Network proxy, DNS, firewall, and TLS metadata for outbound web-protocol communications

Detection direction

  • Treat the absence of MITRE-provided detection guidance as a gap to close with technique-level analytics and incident playbooks.
  • Tune for suspicious Windows service execution and service/task names that resemble legitimate resources, while accounting for administrative software and normal IT operations as false-positive sources.
  • Correlate registry modification or registry-backed storage with process execution, service creation, and outbound network activity rather than alerting on registry activity in isolation.
  • Review outbound HTTP/S-like traffic for uncommon destinations, unusual periodicity, fallback behavior, or encrypted application-layer command-and-control indicators where local logging supports it.
  • Use the Turla relationship as threat-intelligence context for hunting and prioritization, not as proof of attribution in an incident.

Mitigation priorities

  • Ensure Windows endpoints have retained telemetry for process execution, services, registry activity, file activity, and network connections.
  • Restrict and monitor administrative mechanisms that can create or execute services and modify sensitive Registry locations.
  • Harden egress controls and require defensible logging for outbound web protocols, including proxy/DNS/firewall visibility.
  • Maintain incident response procedures for backdoor containment, host isolation, credential review, and scoping of data access or transfer.
  • Use ATT&CK technique mappings for control validation and compliance evidence, since this software object lacks official detection guidance.
Additional notes and limits

TinyTurla is documented by MITRE as a backdoor used by Turla against targets in the US, Germany, and Afghanistan since at least 2020, with Cisco Talos as the cited source. The most actionable defensive content comes from the ATT&CK relationships to techniques such as Registry modification, service execution, command shell execution, web-protocol C2, fallback channels, ingress tool transfer, and scheduled transfer.

The supplied ATT&CK object lists Windows as the platform but does not provide malware-specific detection guidance, aliases, labels, or object-level tactics. Several related techniques have broader platform lists, but this take does not expand TinyTurla platform scope beyond the supplied Windows field. Local telemetry, asset criticality, and incident evidence are required to determine exposure, impact, or attribution.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

TinyTurla

TinyTurla is a backdoor that has been used by Turla against targets in the US, Germany, and Afghanistan since at least 2020.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

14 rows
DomainIDNameRelationship / procedure
EnterpriseT1573.002Asymmetric CryptographySub-technique

TinyTurla has the ability to encrypt C2 traffic with SSL/TLS.[1]

EnterpriseT1106Native API

TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

TinyTurla has been deployed as `w64time.dll` to appear legitimate.[1]

EnterpriseT1569.002Service ExecutionSub-technique

TinyTurla can install itself as a service on compromised machines.[1]

EnterpriseT1112Modify Registry

TinyTurla can set its configuration parameters in the Registry.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

TinyTurla has been installed using a .bat file.[1]

EnterpriseT1105Ingress Tool Transfer

TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware.[1]

EnterpriseT1027.011Fileless StorageSub-technique

TinyTurla can save its configuration parameters in the Registry.[1]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

TinyTurla has mimicked an existing Windows service by being installed as Windows Time Service.[1]

EnterpriseT1029Scheduled Transfer

TinyTurla contacts its C2 based on a scheduled timing set in its configuration.[1]

EnterpriseT1012Query Registry

TinyTurla can query the Registry for its configuration information.[1]

EnterpriseT1008Fallback Channels

TinyTurla can go through a list of C2 server IPs and will try to register with each until one responds.[1]

EnterpriseT1005Data from Local System

TinyTurla can upload files from a compromised host.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

TinyTurla can use HTTPS in C2 communications.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0010: Turla

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
8ec2ed2471fab356...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle8ec2ed2471fa…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  2. [2]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  3. [3]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  4. [4]
    mitre-attackS0668
    Open source URL
  5. [5]
    mitre-attackS0668
    Open source URL
  6. [6]
    mitre-attackS0668
    Open source URL
  7. [7]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  8. [8]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  9. [9]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  10. [10]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  11. [11]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  12. [12]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  13. [13]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  14. [14]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  15. [15]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  16. [16]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  17. [17]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  18. [18]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  19. [19]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  20. [20]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  21. [21]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  22. [22]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  23. [23]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  24. [24]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  25. [25]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  26. [26]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  27. [27]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  28. [28]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  29. [29]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  30. [30]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  31. [31]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  32. [32]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  33. [33]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  34. [34]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.