Turla
MITRE ATT&CK: G0010 View on attack.mitre.org
Aliases: IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, VENOMOUS Bear, WRAITH, Uroburos, Pfinet, TAG_0530, KRYPTON, Hippo Team, Pacifier APT, Popeye, SIG23, MAKERSMARK, ATK13, ITG12, Blue Python, SUMMIT, UNC4210, UAC-0144, UAC-0024, UAC-0003, Turla, ATG26
- First seen
- 2004-01-01 00:00:00
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 449 (433 malicious)
- Last IoC activity
- 2026-09-02 02:39:11
- Profile updated
- 2026-07-07 12:34:09
Targeted industries: government-and-public-sector defense-and-aerospace education-and-nonprofits healthcare-and-pharmaceutical
Context
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.
Recent IoC activity
433 malicious indicators in Maltiverse are attributed to Turla (G0010). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.nullsecurity.net | 2026-09-03 | 1 |
| hostname | ns-3.open.ro | 2026-09-03 | 1 |
| hostname | autodiscover.email | 2026-09-03 | 1 |
| hostname | autodiscover.exchange | 2026-09-03 | 1 |
| hostname | autoconfig.email | 2026-09-03 | 1 |
| hostname | mail.pics | 2026-09-03 | 1 |
| hostname | prod.tools | 2026-09-02 | 1 |
| hostname | webdisk.us | 2026-09-02 | 1 |
| hostname | autodiscover.host | 2026-09-02 | 1 |
| hostname | admin.dev | 2026-09-02 | 1 |
| hostname | autodiscover.it | 2026-09-02 | 1 |
| hostname | made.by | 2026-09-02 | 1 |
| hostname | www.cantrip.org | 2026-09-02 | 1 |
| hostname | test.support | 2026-09-02 | 1 |
| hostname | mail.news | 2026-09-02 | 1 |
| hostname | webdisk.it | 2026-09-02 | 1 |
| hostname | webdisk.de | 2026-09-02 | 1 |
| hostname | autodiscover.online | 2026-09-02 | 1 |
| hostname | secure.dev | 2026-09-02 | 1 |
| hostname | autodiscover.de | 2026-09-02 | 1 |
Detection coverage
- 34 YARA rules
- 966 Sigma rules
Malware & tools used
- Modify Registry (attack-pattern)
- Local Groups (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Tool (attack-pattern)
- JavaScript (attack-pattern)
- Create Process with Token (attack-pattern)
- Visual Basic (attack-pattern)
- PowerShell Profile (attack-pattern)
- Web Services (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Windows Credential Manager (attack-pattern)
- Proxy (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Group Policy Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Native API (attack-pattern)
- Mail Protocols (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Data from Local System (attack-pattern)
- Query Registry (attack-pattern)
- System Service Discovery (attack-pattern)
- Brute Force (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
Related threat objects
- APT26 (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- blog.google — Continued Cyber Activity In Eastern Europe Observed By Tag (report)
- blog.google — Fog Of War How The Ukraine Conflict Transformed The Cyber Threat Landscape (report)
- cip.gov.ua — Download (report)
- circl.lu — Tr 25 (report)
- Kaspersky — 81638 (report)
- Kaspersky — 65545 (report)
- cfr.org — Turla (report)
- nytimes.com — 26Cyber (report)
- Kaspersky — The Penquin Turla 2 (report)
- kaspersky.com — 6713 (report)
- Mandiant — Rpt Witchcoven (report)
- Kaspersky — The Epic Turla Operation (report)
- threatpost.com — 109765 (report)
- Kaspersky — 72081 (report)
- ESET — Turla Mosquito Shift Towards Generic Tools (report)
- first.org — Turla Operations And Development (report)
- yle.fi — 8591548 (report)
- ESET — Carbon Paper Peering Turlas Second Stage Backdoor (report)
- Kaspersky — Satellite Turla Apt Command And Control In The Sky (report)
- nccgroup.trust — Turla Png Dropper Is Back (report)
- Broadcom/Symantec — Waterbug Attack Group (report)
- theguardian.com — Turla Hackers Spying Governments Researcher Kaspersky Symantec (report)
- bleepingcomputer.com — Turla Outlook Backdoor Uses Clever Tactics For Stealth And Persistence (report)
Attributed from
- C0026 (campaign)
External references
- mitre-attack — G0010
- BELUGASTURGEON
- Krypton
- Snake
- Venomous Bear
- Turla
- Group 88
- Secret Blizzard
- IRON HUNTER
- Accenture HyperStack October 2020
- Waterbug
- Talos TinyTurla September 2021
- ESET Turla Mosquito Jan 2018
- ESET Gazer Aug 2017
- ESET Turla PowerShell May 2019
- Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023
- Securelist WhiteBear Aug 2017
- Kaspersky Turla
- Leonardo Turla Penquin May 2020
- CrowdStrike VENOMOUS BEAR