Netskope Threat Labs

Mosquito

ATP Sandbox Adv. Heuristics

Mosquito is a Win32 backdoor used by the Turla threat actor, made up of an installer, a launcher, and a backdoor component called CommanderDLL.

First seen
June 2023
Last seen
October 2026

17 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1546Event Triggered Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1518Software Discovery

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Win32.Trojan.Mosquito