TGTGInsighttelegram intelligenceLIVE / telegram public index
← hackspace

TGINSIGHT SIMILAR POSTS

Find similar content

Source channel @hackspace · Post #1500 · Jan 15

This blog post provides an in-depth analysis of #Turla's #Kazuar v3 loader and how it tries to slip past modern defenses: • Sideloading via MFC satellite DLLs • Control flow redirection trick (+ POC) • Patchless ETW and AMSI bypasses (+ POC) • Extensive COM usage for registry, file and folder operations (+ partial POC) • Strings encryption (+ IDAPython decryption script) • Including IOCs and Yara rules https://r136a1.dev/2026/01/14/command-and-evade-turlas-kazuar-v3-loader/

Results

1 similar post found

General global search

hackspace

@hackspace · Post #1500 · 01/15/2026, 10:17 AM

This blog post provides an in-depth analysis of #Turla's #Kazuar v3 loader and how it tries to slip past modern defenses: • Sideloading via MFC satellite DLLs • Control flow redirection trick (+ POC) • Patchless ETW and AMSI bypasses (+ POC) • Extensive COM usage for registry, file and folder operations (+ partial POC) • Strings encryption (+ IDAPython decryption script) • Including IOCs and Yara rules https://r136a1.dev/2026/01/14/command-and-evade-turlas-kazuar-v3-loader/