# Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries — FSB-Attributed .NET Modular Implant with HP Printer Impersonation

> Turla (Pensive Ursa / Russian FSB) deploys Kazuar V3 .NET backdoor via a novel satellite DLL sideloading technique exploiting MFC (Microsoft Foundation Classes) binaries compiled with Visual Studio .NET 2002–2010. A VBS dropper downloads 5 artifacts from 185.126.255[.]132: a legitimate HP printer driver binary (hpbprndi.exe) that sideloads a malicious MFC satellite DLL (hpbprndiLOC.dll), which decrypts and loads three encrypted .NET Kazuar components in-memory — jayb.dadk (kernel/orchestrator), kgjlj.sil (worker/executor), pkrfsu.ldy (bridge/C2 communications). Persistence via Registry Run key masquerading as 'Hewlett Packard Drivers'. The satellite DLL technique exploits MFC's insecure DLL load fallback behavior — when an MFC binary loads, it searches for language-specific satellite DLLs (appnameLOC.dll) using a predictable search order that can be hijacked.

- **Published:** 2026-02-13T15:24:43Z
- **Last reviewed:** 2026-02-13T15:24:43Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0084
- **ID:** TL-2026-0084
- **Severity:** MEDIUM
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Turla (Russia)
- **Detections:** 12 · **IOCs:** 41 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A Detect FYI analysis disclosed a new delivery and loading mechanism for Turla's Kazuar V3 .NET backdoor, leveraging a previously undocumented technique: satellite DLL sideloading via MFC (Microsoft Foundation Classes) binaries.

The attack begins with a VBS dropper that downloads five artifacts from a staging server at 185.126.255[.]132:
1. hpbprndi.exe — A legitimate HP printer driver binary, an MFC application compiled with Visual Studio .NET 2002–2010
2. hpbprndiLOC.dll — A malicious MFC satellite DLL that acts as the Kazuar loader
3. jayb.dadk — Encrypted .NET component: Kazuar kernel/orchestrator
4. kgjlj.sil — Encrypted .NET component: Kazuar worker/executor
5. pkrfsu.ldy — Encrypted .NET component: Kazuar bridge/C2 communications

All five artifacts are placed in a fake HP printer driver directory: %LOCALAPPDATA%\Programs\HP\Printer\Driver — masquerading as a legitimate HP software installation. The directory path is specifically chosen to appear benign during forensic review.

The satellite DLL sideloading technique exploits a behavior inherent in MFC-compiled applications from the Visual Studio .NET 2002–2010 era. When these MFC binaries initialize, they attempt to load language-specific resource DLLs (satellite DLLs) named with a specific pattern: [appname]LOC.dll (localization DLL). The MFC runtime searches for these satellite DLLs using the standard Windows DLL search order, starting with the application's directory. If a malicious DLL matching the expected name (hpbprndiLOC.dll) is placed in the same directory as the legitimate binary (hpbprndi.exe), it will be loaded automatically when the MFC application starts — without any modification to the legitimate binary.

This is a refinement of traditional DLL sideloading because:
- The legitimate binary is COMPLETELY UNMODIFIED (not patched, not recompiled)
- The satellite DLL naming convention (appnameLOC.dll) is a DOCUMENTED MFC behavior, not a bug
- The sideloaded DLL is loaded during MFC initialization, BEFORE the application's main code executes
- MFC satellite DLL loading does not trigger the same security telemetry as standard DLL loading in some EDR products
- Older MFC binaries (VS .NET 2002–2010) lack modern security features (ASLR entropy, CFG, CET shadow stack)

Once loaded, hpbprndiLOC.dll acts as the Kazuar loader:
1. Reads the three encrypted .NET component files from the same directory
2. Decrypts them in-memory (Kazuar uses AES with RSA-protected keys, per Unit 42's analysis of the Kazuar family)
3. Uses the .NET Assembly.Load(byte[]) method to load the decrypted assemblies directly from memory — no files written to disk
4. The three-component architecture separates concerns: jayb.dadk orchestrates overall operation, kgjlj.sil executes tasks (Kazuar supports 45+ C2 commands), pkrfsu.ldy handles C2 communications

Kazuar V3 represents a significant evolution from earlier versions documented by Unit 42 (2023) and the Ukrainian CERT (2023):
- Supports 45+ C2 commands (up from 26 in 2017 V1)
- Multiple injection modes: inject (explorer.exe), zombify (default browser/svchost), combined, remote, single
- Variable encryption: AES + RSA hybrid, Caesar cipher variants for string encryption, HMACMD5 integrity verification
- Comprehensive system profiling and credential theft targeting Signal messages, source control platforms, and cloud applications
- Anti-analysis: Assembly.Location check (empty string = loaded from byte array), timestamp manipulation (fake 2008 compilation date), custom string obfuscation with multiple dictionaries
- Multithreading model with asynchronous task solver
- Named pipe communication for lateral movement between Kazuar instances

Persistence is established via a Registry Run key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Hewlett Packard Drivers — pointing to hpbprndi.exe in the fake HP directory. The Run key name deliberately impersonates HP driver software to avoid suspicion during manual registry review.

Turla (also tracked as Pensive Ursa, Uroburos, Snake, Venomous Bear, Waterbug, KRYPTON) is attributed to Russia's Federal Security Service (FSB), active since at least 2004. Kazuar has historically targeted the European government and military sectors, with the Ukrainian CERT reporting Kazuar campaigns against the Ukrainian defense sector in 2023.

## MITRE ATT&CK

- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1620 Reflective Code Loading
- T1497 Virtualization/Sandbox Evasion
- T1070 Indicator Removal
- T1055 Process Injection
- T1555 Credentials from Password Stores
- T1056 Input Capture
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1016 System Network Configuration Discovery
- T1057 Process Discovery
- T1518 Software Discovery
- T1005 Data from Local System
- T1113 Screen Capture
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1095 Non-Application Layer Protocol
- T1041 Exfiltration Over C2 Channel
- T1588 Obtain Capabilities
- T1587 Develop Capabilities
- T1608 Stage Capabilities
- T1033 System Owner/User Discovery
- T1583 Acquire Infrastructure
- T1140 Deobfuscate/Decode Files or Information

## Sources

- [Detect FYI — Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries](https://detect.fyi/turla-kazuar-v3-satellite-dll-sideloading-via-mfc-binaries-b5c0e77cffa4)
- [Unit 42 — Over the Kazuar's Nest: Upgraded Kazuar Backdoor (Pensive Ursa)](https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/)
- [CERT-UA — Turla (UAC-0003) Kazuar + Capibar targeting Ukrainian defense](https://cert.gov.ua/article/5213167)
- [Kaspersky — Sunburst/Kazuar code resemblance analysis](https://securelist.com/sunburst-backdoor-kazuar/99981/)
- [US DOJ — Court-Authorized Disruption of Turla Snake Malware](https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network)
- [MITRE ATT&CK — Turla Group Profile (G0010)](https://attack.mitre.org/groups/G0010/)
- [Microsoft — DLL Search Order Documentation](https://learn.microsoft.com/en-us/windows/win32/dlls/dynamic-link-library-search-order)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0084
