Reading some articles about Turla, I found a few mentions of an implant named SilentMoon: https://pinboard.in/u:droberson/t:silentmoon/
This crude rule was able to find a few samples not mentioned in the reports that were not mentioned in the reports bookmarked above.
rule silentmoon
{
meta:
description = "Turla SilentMoon implant"
hash = "a679dbde0f4411396af54ea6ac887bd0488b2339cd8a4b509a01ca5e906f70bd"
strings:
$ = "SilentMoon" wide
condition:
all of them
}
Pingback: Week 05 – 2022 – This Week In 4n6