Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionageremote-access-implantdefense-evasion-methodloader-delivery-mechanism

Turla Deploys Upgraded Kazuar v3 Loader Using COM, ETW, and AMSI Evasion

Updated 16h agoFirst seen Jan 16, 20262 sources

Researchers reported an upgraded Turla Kazuar v3 loader that uses advanced Windows-native evasion and execution techniques, including heavy use of Component Object Model (COM), patchless Event Tracing for Windows (ETW) manipulation, and AMSI bypass methods. The observed multi-stage chain begins with a VBScript (8RWRLT.vbs) that retrieves additional components from attacker infrastructure and stages multiple encrypted Kazuar payloads; analysis indicates the loader can embed execution logic into the Windows COM subsystem to blend into legitimate system activity and increase defender analysis time.

Technical reporting tied the activity to infrastructure and tradecraft consistent with prior reporting on Gamaredon–Turla operational overlap. The VBScript was observed downloading from https://185.126.255[.]132 and creating an HP-themed directory structure under %LOCALAPPDATA%\Programs\HP\..., then deploying a legitimate Hewlett-Packard installer alongside a malicious DLL for DLL sideloading, before decrypting and launching Kazuar payloads. The combination of COM-based execution, ETW/AMSI evasion, and staged encrypted payload delivery indicates a continued focus on stealthy post-compromise tooling rather than opportunistic commodity malware delivery.

Share:
Turla Deploys Upgraded Kazuar v3 Loader Using COM, ETW, and AMSI Evasion
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 15, 20266mo ago

Additional reporting highlights Kazuar v3 ETW and AMSI evasion

Subsequent reporting described the same Kazuar v3 loader as discovered in January 2026 and emphasized its use of hardware breakpoints, vectored exception handling, and NtContinue to bypass Windows ETW and AMSI without patching memory on disk. The coverage also noted the tradecraft’s consistency with prior reporting on Turla collaboration patterns.

Jan 14, 20266mo ago

Researcher publishes technical analysis and detection details

On January 14, 2026, security researcher Dominik Reichel published a reverse-engineering analysis of Turla’s Kazuar v3 loader, detailing its COM-based execution, DLL sideloading, and patchless ETW and AMSI bypasses. The report also released technical indicators including hashes, paths, registry keys, C2 URLs, and YARA rules.

Turla deploys updated Kazuar v3 loader campaign

Turla operated a multi-stage Kazuar v3 infection chain that began with a VBScript downloader, fetched components from command-and-control infrastructure, and used DLL sideloading via a legitimate HP installer to launch the malware. The campaign established persistence, performed host reconnaissance, and executed Kazuar modules through COM surrogate processes for stealth.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Threat actors
2 linked
Malware
1 linked
Affected products
6 linked
Windows.Net FrameworkIda ProIda ProSymantec Endpoint ProtectionMicrosoft Defender
Organizations
11 linked
Palo Alto NetworksEsetKasperskyDoctor WebBroadcomHewlett Packard EnterpriseLet's EncryptSouth Park NetworksAriane ConseilOriginalAPKNorthern Fruit
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.