Turla — APT Profile
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.Also tracked as
IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON
Tools & malware
- apk.cyber_azov Mobile Malware
- Arp Network Reconnaissance
- asp.twoface Web Shell
- asp.unidentified_001 Web Shell
- Carbon Backdoor
- certutil LOLBin
- ComRAT Backdoor
- Crutch Backdoor
- elf.penquin_turla Backdoor
- Empire Post-Exploitation Framework
- Epic Backdoor
- Gazer Backdoor
- HyperStack Backdoor
- IronNetInjector Loader
- js.kopiluwak Backdoor
- js.minijs Backdoor
- js.turla_ff_ext Backdoor
- js.turla_maintools Backdoor
- Kazuar Backdoor
- KOPILUWAK Backdoor
- LightNeuron Backdoor
- LunarLoader Loader
- LunarMail Backdoor
- LunarWeb Backdoor
- Mimikatz Credential Harvesting
- Mosquito Backdoor
- NBTscan Network Reconnaissance
- nbtstat Network Reconnaissance
- Net Network Reconnaissance
- netstat Network Reconnaissance
- osx.uroburos Rootkit
- Penquin Backdoor
- PowerStallion Backdoor
- PsExec Remote Execution
- Reg LOLBin
- Systeminfo Discovery
- Tasklist Discovery
- TinyTurla Backdoor
- Uroburos Rootkit
- win.agent_btz Worm
- win.apollo_shadow Backdoor
- win.cobra Backdoor
- win.comlook Backdoor
- win.crutch Backdoor
- win.delivery_check Backdoor
- win.gazer Backdoor
- win.kazuar Backdoor
- win.ksl0t Backdoor
- win.lightneuron Backdoor
- win.lunarmail Backdoor
- win.minipocket Backdoor
- win.mosquito Backdoor
- win.nautilus Backdoor
- win.netflash Backdoor
- win.neuron Backdoor
- win.newpass Backdoor
- win.outlook_backdoor Backdoor
- win.pelmeni Backdoor
- win.powershellrunner Backdoor
- win.quietcanary Backdoor
Vendor research
- the original report Google Threat Intelligence
- Microsoft Security Blog Microsoft
- How Microsoft names threat actors Microsoft
- IRON HUNTER Secureworks CTU
- Turla uses HyperStack, Carbon, and Kazuar to compromise government entity Accenture
- Meet CrowdStrike’s Adversary of the Month for March: VENOMOUS BEAR Meyers, A
- Introducing WhiteBear Securelist
- The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos Kaspersky
- MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64” Leonardo Turla Penquin
- Turla uses HyperStack, Carbon, and Kazuar to compromise government entity Accenture
- Meet CrowdStrike’s Adversary of the Month for March: VENOMOUS BEAR Crowdstrike
- Secureworks CTU. (n.d.). IRON HUNTER Secureworks
- The Waterbug attack group Symantec
- TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines Talos
- Diplomats in Eastern Europe bitten by a Turla mosquito ESET
- Gazing at Gazer: Turla’s new second stage backdoor ESET
- A dive into Turla PowerShell usage ESET
- Hunting Russian Intelligence “Snake” Malware Joint Cybersecurity Advisory AA23-129A Snake Malware