Threat reportAPTTL-2026-0084

Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries — FSB-Attributed .NET Modular Implant with HP Printer Impersonation

mediumACTIVE

Turla Kazuar V3 (TL-2026-0084) is a medium-severity advanced persistent threat campaign, first published 2026-02-13. It is attributed to Turla (Russia) with high confidence, maps to 31 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 12 detection rules and 41 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
1Turla
Detection rules
12SPL · KQL · Sigma
IOCs
41Indicators of compromise

Key facts for TL-2026-0084

Threat ID
TL-2026-0084
Severity
MEDIUM
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Turla
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
Government, Military, Defense, Diplomatic, Intelligence
Target regions
Europe, Ukraine, NATO Countries, Eastern Europe, Western Europe
Detection rules
12
Indicators of compromise
41

Malware and tooling in Turla Kazuar V3

Malware and tooling: Kazuar

How Turla Kazuar V3 works

Turla (Pensive Ursa / Russian FSB) deploys Kazuar V3 .NET backdoor via a novel satellite DLL sideloading technique exploiting MFC (Microsoft Foundation Classes) binaries compiled with Visual Studio .NET 2002–2010. A VBS dropper downloads 5 artifacts from 185.126.255[.]132: a legitimate HP printer driver binary (hpbprndi.exe) that sideloads a malicious MFC satellite DLL (hpbprndiLOC.dll), which decrypts and loads three encrypted .NET Kazuar components in-memory — jayb.dadk (kernel/orchestrator), kgjlj.sil (worker/executor), pkrfsu.ldy (bridge/C2 communications). Persistence via Registry Run key masquerading as 'Hewlett Packard Drivers'. The satellite DLL technique exploits MFC's insecure DLL load fallback behavior — when an MFC binary loads, it searches for language-specific satellite DLLs (appnameLOC.dll) using a predictable search order that can be hijacked.

A Detect FYI analysis disclosed a new delivery and loading mechanism for Turla's Kazuar V3 .NET backdoor, leveraging a previously undocumented technique: satellite DLL sideloading via MFC (Microsoft Foundation Classes) binaries.

The attack begins with a VBS dropper that downloads five artifacts from a staging server at 185.126.255[.]132: 1. hpbprndi.exe — A legitimate HP printer driver binary, an MFC application compiled with Visual Studio .NET 2002–2010 2. hpbprndiLOC.dll — A malicious MFC satellite DLL that acts as the Kazuar loader 3. jayb.dadk — Encrypted .NET component: Kazuar kernel/orchestrator 4. kgjlj.sil — Encrypted .NET component: Kazuar worker/executor 5. pkrfsu.ldy — Encrypted .NET component: Kazuar bridge/C2 communications

All five artifacts are placed in a fake HP printer driver directory: %LOCALAPPDATA%\Programs\HP\Printer\Driver — masquerading as a legitimate HP software installation. The directory path is specifically chosen to appear benign during forensic review.

The satellite DLL sideloading technique exploits a behavior inherent in MFC-compiled applications from the Visual Studio .NET 2002–2010 era. When these MFC binaries initialize, they attempt to load language-specific resource DLLs (satellite DLLs) named with a specific pattern: [appname]LOC.dll (localization DLL). The MFC runtime searches for these satellite DLLs using the standard Windows DLL search order, starting with the application's directory. If a malicious DLL matching the expected name (hpbprndiLOC.dll) is placed in the same directory as the legitimate binary (hpbprndi.exe), it will be loaded automatically when the MFC application starts — without any modification to the legitimate binary.

This is a refinement of traditional DLL sideloading because: - The legitimate binary is COMPLETELY UNMODIFIED (not patched, not recompiled) - The satellite DLL naming convention (appnameLOC.dll) is a DOCUMENTED MFC behavior, not a bug - The sideloaded DLL is loaded during MFC initialization, BEFORE the application's main code executes - MFC satellite DLL loading does not trigger the same security telemetry as standard DLL loading in some EDR products - Older MFC binaries (VS .NET 2002–2010) lack modern security features (ASLR entropy, CFG, CET shadow stack)

Once loaded, hpbprndiLOC.dll acts as the Kazuar loader: 1. Reads the three encrypted .NET component files from the same directory 2. Decrypts them in-memory (Kazuar uses AES with RSA-protected keys, per Unit 42's analysis of the Kazuar family) 3. Uses the .NET Assembly.Load(byte[]) method to load the decrypted assemblies directly from memory — no files written to disk 4. The three-component architecture separates concerns: jayb.dadk orchestrates overall operation, kgjlj.sil executes tasks (Kazuar supports 45+ C2 commands), pkrfsu.ldy handles C2 communications

Kazuar V3 represents a significant evolution from earlier versions documented by Unit 42 (2023) and the Ukrainian CERT (2023): - Supports 45+ C2 commands (up from 26 in 2017 V1) - Multiple injection modes: inject (explorer.exe), zombify (default browser/svchost), combined, remote, single - Variable encryption: AES + RSA hybrid, Caesar cipher variants for string encryption, HMACMD5 integrity verification - Comprehensive system profiling and credential theft targeting Signal messages, source control platforms, and cloud applications - Anti-analysis: Assembly.Location check (empty string = loaded from byte array), timestamp manipulation (fake 2008 compilation date), custom string obfuscation with multiple dictionaries - Multithreading model with asynchronous task solver - Named pipe communication for lateral movement between Kazuar instances

Persistence is established via a Registry Run key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Hewlett Packard Drivers — pointing to hpbprndi.exe in the fake HP directory. The Run key name deliberately impersonates HP driver software to avoid suspicion during manual registry review.

Turla (also tracked as Pensive Ursa, Uroburos, Snake, Venomous Bear, Waterbug, KRYPTON) is attributed to Russia's Federal Security Service (FSB), active since at least 2004. Kazuar has historically targeted the European government and military sectors, with the Ukrainian CERT reporting Kazuar campaigns against the Ukrainian defense sector in 2023.

MITRE ATT&CK techniques used in TL-2026-0084

collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1213 Data from Information Repositories

discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer

persistence

T1547 Boot or Logon Autostart Execution; T1574 Hijack Execution Flow

credential-access

T1555 Credentials from Password Stores

initial-access

T1566 Phishing

resource-development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Remediation for Turla Kazuar V3

Immediate actions

  • Hunt for hpbprndi.exe in %LOCALAPPDATA%\Programs\HP\Printer\Driver\ — this is NOT a legitimate HP installation path
  • Check Registry Run key: HKCU\...\Run\Hewlett Packard Drivers — legitimate HP drivers do NOT use this registry value name
  • Block C2 IP 185.126.255[.]132 at network perimeter
  • Search for files with extensions .dadk, .sil, .ldy in user profile directories — Kazuar encrypted component extensions
  • Monitor for hpbprndiLOC.dll in any directory alongside hpbprndi.exe

Workarounds

  • Remove or rename legacy MFC binaries that are no longer needed — reduces sideloading attack surface
  • Deploy endpoint detection rules for *LOC.dll files loaded from user-writable directories
  • Configure email/web gateway to block VBS file delivery

Longer-term hardening

  • Implement DLL allowlisting via Windows Defender Application Control (WDAC) or AppLocker to prevent unauthorized DLL loading
  • Deploy Sysmon with DLL load monitoring (Event ID 7) for MFC satellite DLL patterns (*LOC.dll)
  • Audit legitimate MFC binaries in enterprise environments — identify which can be abused for satellite DLL sideloading
  • Monitor Assembly.Load(byte[]) calls from non-development processes — indicates in-memory .NET assembly loading
  • Implement least-privilege execution to prevent VBS dropper from creating directories and downloading files

Weaknesses (CWE) in Turla Kazuar V3

CWE-426, CWE-427

Timeline of Turla Kazuar V3

  • Turla (Pensive Ursa) has been active since at least 2004, attributed to Russian Federal Security Service (FSB).
  • Unit 42 first discovers and publicly documents Kazuar .NET backdoor. Initial version supports 26 C2 commands. Source: https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/
  • Kaspersky identifies code resemblance between SolarWinds Sunburst backdoor and Kazuar, demonstrating Kazuar's complexity level. Source: https://securelist.com/sunburst-backdoor-kazuar/99981/
  • US DOJ announces court-authorized disruption of Turla's Snake malware network, confirming FSB attribution. Source: https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network
  • Ukrainian CERT reports Turla (UAC-0003) deploying upgraded Kazuar variant against Ukrainian defense sector, targeting Signal messages and cloud platforms. Source: https://cert.gov.ua/article/5213167
  • Unit 42 publishes deep technical analysis of upgraded Kazuar variant: 45 C2 commands, multiple injection modes, variable encryption, anti-analysis. Source: https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/
  • Kazuar V3 observed with novel satellite DLL sideloading via MFC binaries. VBS dropper downloads 5 artifacts from 185.126.255[.]132 to fake HP printer directory.
  • Threadlinqs Intelligence issues TL-2026-0084 covering Turla Kazuar V3 satellite DLL sideloading, MFC exploitation, three-component encrypted .NET architecture, and fake HP printer persistence.
  • Detect FYI publishes analysis of Turla Kazuar V3 satellite DLL sideloading technique via MFC binaries (hpbprndi.exe + hpbprndiLOC.dll). Source: https://detect.fyi/turla-kazuar-v3-satellite-dll-sideloading-via-mfc-binaries-b5c0e77cffa4
  • As of 2026-05-29, this threat remains ACTIVE: Turla/Secret Blizzard (FSB Center 16) is still operating with no takedown, and Microsoft (May 14 2026), BleepingComputer and Security Affairs confirm Kazuar's continued evolution into a modular P2P botnet. No CVE/KEV applies (MFC fallback abuse, CWE-426/427), and the Kazuar V3 loader technique is corroborated by R136a1 and Detect FYI research.

Sources cited for Turla Kazuar V3

Detection coverage for TL-2026-0084

As of 2026-02-13, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0084 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
41 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats