Also known as: IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, Turla Team, Uroburos, SIG23, MAKERSMARK, Skipper Turla, WRAITH, Pfinet, TAG_0530, Hippo Team, Pacifier APT, Popeye, ATK13, G0010, ITG12, Blue Python, SUMMIT, UNC4210, UAC-0144, UAC-0024, UAC-0003, Turbine Panda, APT26, JerseyMikes, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, TURLA RELIC
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.(Citation: Kaspersky Turla)(Citation: ESET Gazer Aug 2017)(Citation: CrowdStrike VENOMOUS BEAR)(Citation: ESET Turla Mosquito Jan 2018)(Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023)
Satellite Turla; Epic Turla; The 'Penquin' Turla; Witchcoven; RUAG hack; Mosquito; Moonlight Maze
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Turla is a sophisticated Russian cyber espionage group linked to the FSB, targeting critical sectors globally since at least 2004. Known for advanced malware like Uroburos and leveraging multiple attack vectors, Turla poses significant risks to government and defense infrastructure through persistent, targeted campaigns.
Goals & Targeting
Turla's primary goal appears to be espionage, with a focus on compromising government entities, defense industries, and other sectors that hold strategic information of interest to Russian interests. Their targeting of Ukraine suggests a geopolitical focus aligned with broader Russian foreign policy objectives.
Enhanced Description
Turla is a state-sponsored cyber espionage group attributed to Russia's Federal Security Service (FSB). Since first being identified in 2004, this group has conducted operations across over 50 countries, with a particular focus on government, defense, energy, aerospace, and legal sectors. Their campaign patterns include watering hole attacks, spear-phishing, and the deployment of custom malware such as Uroburos, Gazer, and Carbon. Turla is known for long-term, patient campaigns designed to gather sensitive intelligence from targeted organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Turla has been involved in numerous high-profile campaigns, including the 'RUAG hack' and operations under aliases like 'VENOMOUS Bear'. Their campaigns often exhibit long-term persistence and use of custom tools designed for specific espionage purposes.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Turla's FSB affiliation and targeting patterns, but some tool origins remain unclear. IOC data and campaign links provide strong evidence of their activities over time.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
68
Techniques
26
Tools
9
Campaigns
225
IOCs
0
Observed Data
13
Tactics