Threat reportAPTTL-2026-0084
Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries — FSB-Attributed .NET Modular Implant with HP Printer Impersonation
Turla Kazuar V3 (TL-2026-0084) is a medium-severity advanced persistent threat campaign, first published 2026-02-13. It is attributed to Turla (Russia) with high confidence, maps to 31 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 12 detection rules and 41 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 31MITRE ATT&CK
- Actors
- 1Turla
- Detection rules
- 12SPL · KQL · Sigma
- IOCs
- 41Indicators of compromise
Key facts for TL-2026-0084
- Threat ID
- TL-2026-0084
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Turla
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- Government, Military, Defense, Diplomatic, Intelligence
- Target regions
- Europe, Ukraine, NATO Countries, Eastern Europe, Western Europe
- Detection rules
- 12
- Indicators of compromise
- 41
Malware and tooling in Turla Kazuar V3
Malware and tooling: Kazuar
How Turla Kazuar V3 works
Turla (Pensive Ursa / Russian FSB) deploys Kazuar V3 .NET backdoor via a novel satellite DLL sideloading technique exploiting MFC (Microsoft Foundation Classes) binaries compiled with Visual Studio .NET 2002–2010. A VBS dropper downloads 5 artifacts from 185.126.255[.]132: a legitimate HP printer driver binary (hpbprndi.exe) that sideloads a malicious MFC satellite DLL (hpbprndiLOC.dll), which decrypts and loads three encrypted .NET Kazuar components in-memory — jayb.dadk (kernel/orchestrator), kgjlj.sil (worker/executor), pkrfsu.ldy (bridge/C2 communications). Persistence via Registry Run key masquerading as 'Hewlett Packard Drivers'. The satellite DLL technique exploits MFC's insecure DLL load fallback behavior — when an MFC binary loads, it searches for language-specific satellite DLLs (appnameLOC.dll) using a predictable search order that can be hijacked.
A Detect FYI analysis disclosed a new delivery and loading mechanism for Turla's Kazuar V3 .NET backdoor, leveraging a previously undocumented technique: satellite DLL sideloading via MFC (Microsoft Foundation Classes) binaries.
The attack begins with a VBS dropper that downloads five artifacts from a staging server at 185.126.255[.]132: 1. hpbprndi.exe — A legitimate HP printer driver binary, an MFC application compiled with Visual Studio .NET 2002–2010 2. hpbprndiLOC.dll — A malicious MFC satellite DLL that acts as the Kazuar loader 3. jayb.dadk — Encrypted .NET component: Kazuar kernel/orchestrator 4. kgjlj.sil — Encrypted .NET component: Kazuar worker/executor 5. pkrfsu.ldy — Encrypted .NET component: Kazuar bridge/C2 communications
All five artifacts are placed in a fake HP printer driver directory: %LOCALAPPDATA%\Programs\HP\Printer\Driver — masquerading as a legitimate HP software installation. The directory path is specifically chosen to appear benign during forensic review.
The satellite DLL sideloading technique exploits a behavior inherent in MFC-compiled applications from the Visual Studio .NET 2002–2010 era. When these MFC binaries initialize, they attempt to load language-specific resource DLLs (satellite DLLs) named with a specific pattern: [appname]LOC.dll (localization DLL). The MFC runtime searches for these satellite DLLs using the standard Windows DLL search order, starting with the application's directory. If a malicious DLL matching the expected name (hpbprndiLOC.dll) is placed in the same directory as the legitimate binary (hpbprndi.exe), it will be loaded automatically when the MFC application starts — without any modification to the legitimate binary.
This is a refinement of traditional DLL sideloading because: - The legitimate binary is COMPLETELY UNMODIFIED (not patched, not recompiled) - The satellite DLL naming convention (appnameLOC.dll) is a DOCUMENTED MFC behavior, not a bug - The sideloaded DLL is loaded during MFC initialization, BEFORE the application's main code executes - MFC satellite DLL loading does not trigger the same security telemetry as standard DLL loading in some EDR products - Older MFC binaries (VS .NET 2002–2010) lack modern security features (ASLR entropy, CFG, CET shadow stack)
Once loaded, hpbprndiLOC.dll acts as the Kazuar loader: 1. Reads the three encrypted .NET component files from the same directory 2. Decrypts them in-memory (Kazuar uses AES with RSA-protected keys, per Unit 42's analysis of the Kazuar family) 3. Uses the .NET Assembly.Load(byte[]) method to load the decrypted assemblies directly from memory — no files written to disk 4. The three-component architecture separates concerns: jayb.dadk orchestrates overall operation, kgjlj.sil executes tasks (Kazuar supports 45+ C2 commands), pkrfsu.ldy handles C2 communications
Kazuar V3 represents a significant evolution from earlier versions documented by Unit 42 (2023) and the Ukrainian CERT (2023): - Supports 45+ C2 commands (up from 26 in 2017 V1) - Multiple injection modes: inject (explorer.exe), zombify (default browser/svchost), combined, remote, single - Variable encryption: AES + RSA hybrid, Caesar cipher variants for string encryption, HMACMD5 integrity verification - Comprehensive system profiling and credential theft targeting Signal messages, source control platforms, and cloud applications - Anti-analysis: Assembly.Location check (empty string = loaded from byte array), timestamp manipulation (fake 2008 compilation date), custom string obfuscation with multiple dictionaries - Multithreading model with asynchronous task solver - Named pipe communication for lateral movement between Kazuar instances
Persistence is established via a Registry Run key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Hewlett Packard Drivers — pointing to hpbprndi.exe in the fake HP directory. The Run key name deliberately impersonates HP driver software to avoid suspicion during manual registry review.
Turla (also tracked as Pensive Ursa, Uroburos, Snake, Venomous Bear, Waterbug, KRYPTON) is attributed to Russia's Federal Security Service (FSB), active since at least 2004. Kazuar has historically targeted the European government and military sectors, with the Ukrainian CERT reporting Kazuar campaigns against the Ukrainian defense sector in 2023.
MITRE ATT&CK techniques used in TL-2026-0084
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1213 Data from Information Repositories
discovery
T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer
persistence
T1547 Boot or Logon Autostart Execution; T1574 Hijack Execution Flow
credential-access
T1555 Credentials from Password Stores
initial-access
resource-development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Remediation for Turla Kazuar V3
Immediate actions
- Hunt for hpbprndi.exe in %LOCALAPPDATA%\Programs\HP\Printer\Driver\ — this is NOT a legitimate HP installation path
- Check Registry Run key: HKCU\...\Run\Hewlett Packard Drivers — legitimate HP drivers do NOT use this registry value name
- Block C2 IP 185.126.255[.]132 at network perimeter
- Search for files with extensions .dadk, .sil, .ldy in user profile directories — Kazuar encrypted component extensions
- Monitor for hpbprndiLOC.dll in any directory alongside hpbprndi.exe
Workarounds
- Remove or rename legacy MFC binaries that are no longer needed — reduces sideloading attack surface
- Deploy endpoint detection rules for *LOC.dll files loaded from user-writable directories
- Configure email/web gateway to block VBS file delivery
Longer-term hardening
- Implement DLL allowlisting via Windows Defender Application Control (WDAC) or AppLocker to prevent unauthorized DLL loading
- Deploy Sysmon with DLL load monitoring (Event ID 7) for MFC satellite DLL patterns (*LOC.dll)
- Audit legitimate MFC binaries in enterprise environments — identify which can be abused for satellite DLL sideloading
- Monitor Assembly.Load(byte[]) calls from non-development processes — indicates in-memory .NET assembly loading
- Implement least-privilege execution to prevent VBS dropper from creating directories and downloading files
Weaknesses (CWE) in Turla Kazuar V3
Timeline of Turla Kazuar V3
- Turla (Pensive Ursa) has been active since at least 2004, attributed to Russian Federal Security Service (FSB).
- Unit 42 first discovers and publicly documents Kazuar .NET backdoor. Initial version supports 26 C2 commands. Source: https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/
- Kaspersky identifies code resemblance between SolarWinds Sunburst backdoor and Kazuar, demonstrating Kazuar's complexity level. Source: https://securelist.com/sunburst-backdoor-kazuar/99981/
- US DOJ announces court-authorized disruption of Turla's Snake malware network, confirming FSB attribution. Source: https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network
- Ukrainian CERT reports Turla (UAC-0003) deploying upgraded Kazuar variant against Ukrainian defense sector, targeting Signal messages and cloud platforms. Source: https://cert.gov.ua/article/5213167
- Unit 42 publishes deep technical analysis of upgraded Kazuar variant: 45 C2 commands, multiple injection modes, variable encryption, anti-analysis. Source: https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/
- Kazuar V3 observed with novel satellite DLL sideloading via MFC binaries. VBS dropper downloads 5 artifacts from 185.126.255[.]132 to fake HP printer directory.
- Threadlinqs Intelligence issues TL-2026-0084 covering Turla Kazuar V3 satellite DLL sideloading, MFC exploitation, three-component encrypted .NET architecture, and fake HP printer persistence.
- Detect FYI publishes analysis of Turla Kazuar V3 satellite DLL sideloading technique via MFC binaries (hpbprndi.exe + hpbprndiLOC.dll). Source: https://detect.fyi/turla-kazuar-v3-satellite-dll-sideloading-via-mfc-binaries-b5c0e77cffa4
- As of 2026-05-29, this threat remains ACTIVE: Turla/Secret Blizzard (FSB Center 16) is still operating with no takedown, and Microsoft (May 14 2026), BleepingComputer and Security Affairs confirm Kazuar's continued evolution into a modular P2P botnet. No CVE/KEV applies (MFC fallback abuse, CWE-426/427), and the Kazuar V3 loader technique is corroborated by R136a1 and Detect FYI research.
Sources cited for Turla Kazuar V3
- Detect FYI — Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries
- Unit 42 — Over the Kazuar's Nest: Upgraded Kazuar Backdoor (Pensive Ursa)
- CERT-UA — Turla (UAC-0003) Kazuar + Capibar targeting Ukrainian defense
- Kaspersky — Sunburst/Kazuar code resemblance analysis
- US DOJ — Court-Authorized Disruption of Turla Snake Malware
- MITRE ATT&CK — Turla Group Profile (G0010)
- Microsoft — DLL Search Order Documentation
Detection coverage for TL-2026-0084
As of 2026-02-13, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0084 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.