Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

2026-05-16T07:24:09Zc2c1dfcfb0c5797f38af0c54bcff463257ab31a92d9c96213943bb204284ccc5
Cisco SD-WANClaw-ChainEximKazuarMicrosoft ExchangeNGINXOpenClawP2P-botnetPraisonAITanStackTurlaactive-exploitationauthentication-bypassbackdoorknown-exploited-vulnerabilitylocal-privilege-escalationmail-transfer-agentmalicious-packagesnode-ipcprivilege-escalationremote-code-executionrubyGemsstate-sponsoredsupply-chainsupply-chain-compromise

What happened

A wave of high‑severity incidents and disclosures: Russian group Turla has refactored its Kazuar backdoor into a modular P2P botnet for stealthy persistent access, while multiple high‑impact vulnerabilities across enterprise infrastructure are being disclosed and actively exploited. Notable issues include a critical authentication‑bypass in Cisco Catalyst SD‑WAN (CVE‑2026‑20182) now on CISA's KEV list and under active exploitation, an Exchange Server XSS/spoofing exploit (CVE‑2026‑42897) used in the wild, Exim Dead.Letter BDAT code‑execution (CVE‑2026‑45185), an 18‑year NGINX rewrite module RⱯ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c2c1dfcfb0c5797f38af0c54bcff463257ab31a92d9c96213943bb204284ccc5
Enrichment time
2026-05-16T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access · Baitaphish