In a new reconnaissance campaign, the Russian state-run hacking group Turla was observed targeting the Austrian Economic Chamber, a NATO platform, and the Baltic Defense College.
This discovery comes from cybersecurity firm Sekoia, which built on previous findings by Google's TAG, which this year tracked Russian hackers.
Google warned of coordinated activity by Russia-based threat groups in late March 2022, while in May, it identified two Turla domains used in ongoing campaigns.
Sekoia used this information to investigate further and found that Turla was targeting the federal organization in Austria and the military college in the Baltic region.
See also: Ransomware attack on Chicago school exposes data of 500,000 students

Who is Turla?
Turla is a Russian-speaking cyberespionage group believed to have strong ties to the Russian Federation's FSB. It has been operating since at least 2014, breaching a wide range of organizations in multiple countries.
In the past, they had targeted Microsoft Exchange around the world to deploy backdoors, hijacked the infrastructure of other APTs to conduct espionage in the Middle East , and carried out attacks against Armenian targets.
More recently, Turla has been seen using a variety of backdoors and remote access trojans against EU governments and embassies and major research facilities.
See also: PDF attachments with embedded Word documents distribute malware
European goals
According to Sekoia, the IPs sharing Google's TAG lead to the domains “baltdefcol.webredirect[.]org” and “wkoinfo.webredirect[.]org”, which respectively typo-squat “baltdefcol.org” and “wko.at.”
The first target, BALTDEFCOL, is a military college located in Estonia and operated by Estonia, Latvia and Lithuania, and functions as a center for strategic and operational research in the Baltics.
The college also organizes conferences attended by high-ranking officers from NATO and various European countries, so it is of particular importance to Russia in the ongoing conflict in Ukraine and tensions on the Russian border.
The WKO (Wirtschaftskammer Österreich) is the Federal Economic Chamber of Austria, which acts as an international advisor on legislation and economic sanctions.
Austria has maintained a neutral stance on sanctions against Russia, but Turla would like to be among the first to know if anything changes on that front.
Sekoia also identified a third typo-squat domain, “jadlactnato.webredirect[.]org”, which attempts to pass itself off as an e-learning portal for NATO.
See also: GoodWill ransomware: Its goal is to get victims to donate to the poor
Perform recognition
The typosquatting domains are used to host a malicious Word named “War Bulletin 19.00 CET 27.04.docx”, which is found in various directories of these sites.
This file contains an embedded PNG (logo.png), which is retrieved when the document is loaded. The Word file does not contain any malicious macros or behavior, leading Sekoia to believe that the PNG is being used to perform reconnaissance.
Additionally, Turla gains access to the victim 's IP address , which would be useful in later phases of the attack.
To allow defenders to detect this activity, Sekoia has provided the following Yara rule:

Information source: bleepingcomputer.com
