Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, Turla Team, Uroburos, SIG23, MAKERSMARK, Skipper Turla, WRAITH, Pfinet, TAG_0530, Hippo Team, Pacifier APT, Popeye, ATK13, G0010, ITG12, Blue Python, SUMMIT, UNC4210, UAC-0144, UAC-0024, UAC-0003, Turbine Panda, APT26, JerseyMikes, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, TURLA RELIC

Description

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.(Citation: Kaspersky Turla)(Citation: ESET Gazer Aug 2017)(Citation: CrowdStrike VENOMOUS BEAR)(Citation: ESET Turla Mosquito Jan 2018)(Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023)

TTP Summary

Satellite Turla; Epic Turla; The 'Penquin' Turla; Witchcoven; RUAG hack; Mosquito; Moonlight Maze

Goals & Targeting

Targeted Sectors

Government
Defense
Energy
Aerospace & defense
Legal

Targeted Countries / Regions

Ukraine

AI Analysis

· 1 week ago

Executive Summary

Turla is a sophisticated Russian cyber espionage group linked to the FSB, targeting critical sectors globally since at least 2004. Known for advanced malware like Uroburos and leveraging multiple attack vectors, Turla poses significant risks to government and defense infrastructure through persistent, targeted campaigns.

Goals & Targeting

Turla's primary goal appears to be espionage, with a focus on compromising government entities, defense industries, and other sectors that hold strategic information of interest to Russian interests. Their targeting of Ukraine suggests a geopolitical focus aligned with broader Russian foreign policy objectives.

Enhanced Description

Turla is a state-sponsored cyber espionage group attributed to Russia's Federal Security Service (FSB). Since first being identified in 2004, this group has conducted operations across over 50 countries, with a particular focus on government, defense, energy, aerospace, and legal sectors. Their campaign patterns include watering hole attacks, spear-phishing, and the deployment of custom malware such as Uroburos, Gazer, and Carbon. Turla is known for long-term, patient campaigns designed to gather sensitive intelligence from targeted organizations.

Key Capabilities

  • Custom malware development
  • Advanced persistence techniques
  • Watering hole attacks
  • Spear-phishing campaigns
  • Malware deployment

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Discovery

ATT&CK Techniques

T1059.003
T1087.002
T1546.013
T1069.002
T1005
T1055
T1071.003
T1112
T1083
T1027.010

Software / Tooling

Uroburos
Gazer
LunarLoader
Crutch
Mosquito
KOPILUWAK

Campaigns & Victims

Turla has been involved in numerous high-profile campaigns, including the 'RUAG hack' and operations under aliases like 'VENOMOUS Bear'. Their campaigns often exhibit long-term persistence and use of custom tools designed for specific espionage purposes.

IOC Patterns

  • Malware hashes: e298b83891b192b8a2782e638e7f5601acf13bab2f619215ac68a0b61230a273
  • Domain: connectotels.net
  • IP addresses: 94.177.198.94, 162.213.195.129

Recommended Actions

  • Monitor for known Turla malware hashes in network traffic.
  • Implement multi-factor authentication for critical systems.
  • Conduct regular security audits focusing on government and defense infrastructure.

Suggested Tags

APT
espionage
government
defense

Confidence Assessment

High confidence in Turla's FSB affiliation and targeting patterns, but some tool origins remain unclear. IOC data and campaign links provide strong evidence of their activities over time.

ATT&CK Techniques

Command & Control
7 techniques
Discovery
18 techniques
Execution
7 techniques
Resource Development
7 techniques
Stealth
10 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 URL 2

References

  1. Accenture HyperStack October 2020 — Accenture. (2020, October). Turla uses HyperStack, Carbon, and Kazuar to compromise government entity. Retrieved December 2, 2020.
  2. Talos TinyTurla September 2021 — Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.
  3. ESET Turla Mosquito Jan 2018 — ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.
  4. ESET Gazer Aug 2017 — ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.
  5. ESET Turla PowerShell May 2019 — Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.
  6. Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023 — FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.
  7. Securelist WhiteBear Aug 2017 — Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.
  8. Kaspersky Turla — Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.
  9. Leonardo Turla Penquin May 2020 — Leonardo. (2020, May 29). MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64”. Retrieved March 11, 2021.
  10. CrowdStrike VENOMOUS BEAR — Meyers, A. (2018, March 12). Meet CrowdStrike’s Adversary of the Month for March: VENOMOUS BEAR. Retrieved May 16, 2018.
  11. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  12. Secureworks IRON HUNTER Profile — Secureworks CTU. (n.d.). IRON HUNTER. Retrieved February 22, 2022.
  13. Symantec Waterbug — Symantec. (2015, January 26). The Waterbug attack group. Retrieved April 10, 2015.

Intel Summary

68

Techniques

26

Tools

9

Campaigns

225

IOCs

0

Observed Data

13

Tactics

Tags

APT
Healthcare Targeting
Phishing
Government Targeting
espionage
government
defense

Details

MITRE ID
G0010
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--7a19ecb1-3c65-4de3-a230-993516aed6a6
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.