Netskope Threat Labs

Octopus

ATP Sandbox Adv. Heuristics

Octopus is a tool that researchers have associated with the Turla threat group, delivered to victims through compromised websites and trojanized software. It acts as a first stage that profiles the victim and can pull down heavier payloads on compromised systems.

First seen
April 2022
Last seen
September 2026

19 techniques across 8 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1680Local Storage Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
  • T1567Exfiltration Over Web Service
Alert Name
Win32.Trojan.Octopus