Turla — APT Profile
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, WRAITH, Pfinet, TAG_0530, Hippo Team, Pacifier APT, Popeye, SIG23, MAKERSMARK, ATK13, G0010, ITG12, Blue Python, SUMMIT, UNC4210, UAC-0144, UAC-0024, UAC-0003, TURLA RELIC, Skipper Turla
IntelFusions coverage (9)
- Russia's spies phish by asking you to link your WhatsApp 2026-08-20 · Nation-State
- Satellite attacks went from TV pranks to wiper malware 2026-08-06 · Cyber Incidents
- Extortion crew that hit dental offices now claims US IT providers 2026-07-27 · Ransomware
- US Agencies Warn Russian Spies Still Phishing Messaging Apps 2026-06-27 · Nation-State
- Russia's Gamaredon hides Ukraine spying behind everyday web services 2026-06-26 · Nation-State
- Russia's FSB-linked Turla hits Ukraine with a stealthy new backdoor 2026-06-25 · Nation-State
- Russia-aligned hackers keep hitting Ukraine through an old WinRAR bug 2026-06-09 · Nation-State
- Secret Blizzard (Turla/FSB Center 16) ISP-Level AiTM Against Moscow Embassies: ApolloShadow Malware Installs Kaspersky-Masquerading Root Certificates and UpdatusUser Hidden Admin 2026-02-16 · Nation-State
- Gamaredon Group: Russia's Most Prolific APT Against Ukraine, Powered by Custom Malware and SFX Persistence 2026-02-16 · Nation-State
Tools & malware
- apk.cyber_azov Mobile Malware
- Arp Network Reconnaissance
- asp.twoface Web Shell
- asp.unidentified_001 Web Shell
- Carbon Backdoor
- certutil LOLBin
- ComRAT Backdoor
- Crutch Backdoor
- elf.penquin_turla Backdoor
- Empire Post-Exploitation Framework
- Epic Backdoor
- Gazer Backdoor
- HyperStack Backdoor
- IronNetInjector Loader
- js.kopiluwak Backdoor
- js.minijs Backdoor
- js.turla_ff_ext Backdoor
- js.turla_maintools Backdoor
- Kazuar Backdoor
- KOPILUWAK Backdoor
- LightNeuron Backdoor
- LunarLoader Loader
- LunarMail Backdoor
- LunarWeb Backdoor
- Mimikatz Credential Harvesting
- Mosquito Backdoor
- NBTscan Network Reconnaissance
- nbtstat Network Reconnaissance
- Net Network Reconnaissance
- netstat Network Reconnaissance
- osx.uroburos Rootkit
- Penquin Backdoor
- PowerStallion Backdoor
- PsExec Remote Execution
- Reg LOLBin
- Systeminfo Discovery
- Tasklist Discovery
- TinyTurla Backdoor
- Uroburos Rootkit
- win.agent_btz Worm
- win.apollo_shadow Backdoor
- win.cobra Backdoor
- win.comlook Backdoor
- win.crutch Backdoor
- win.delivery_check Backdoor
- win.gazer Backdoor
- win.kazuar Backdoor
- win.ksl0t Backdoor
- win.lightneuron Backdoor
- win.lunarmail Backdoor
- win.minipocket Backdoor
- win.mosquito Backdoor
- win.nautilus Backdoor
- win.netflash Backdoor
- win.neuron Backdoor
- win.newpass Backdoor
- win.outlook_backdoor Backdoor
- win.pelmeni Backdoor
- win.powershellrunner Backdoor
- win.quietcanary Backdoor
Vendor research
- IRON HUNTER Secureworks CTU
- the original report Google Threat Intelligence
- Microsoft Security Blog Microsoft
- How Microsoft names threat actors Microsoft
- Turla uses HyperStack, Carbon, and Kazuar to compromise government entity Accenture
- Meet CrowdStrike’s Adversary of the Month for March: VENOMOUS BEAR Meyers, A
- Introducing WhiteBear Securelist
- The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos Kaspersky
- MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64” Leonardo Turla Penquin
- Turla uses HyperStack, Carbon, and Kazuar to compromise government entity Accenture
- Meet CrowdStrike’s Adversary of the Month for March: VENOMOUS BEAR Crowdstrike
- Secureworks CTU. (n.d.). IRON HUNTER Secureworks
- The Waterbug attack group Symantec
- TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines Talos
- Diplomats in Eastern Europe bitten by a Turla mosquito ESET
- Gazing at Gazer: Turla’s new second stage backdoor ESET
- A dive into Turla PowerShell usage ESET
- Hunting Russian Intelligence “Snake” Malware Joint Cybersecurity Advisory AA23-129A Snake Malware
Countries linked to this actor
- Estonia targets
- Finland targets
- France targets
- Italy targets
- Czech Republic targets
- Switzerland targets
- Ukraine targets
- Armenia targets
- Romania targets
- Austria targets
- Spain targets
- Afghanistan targets