Turla

MITRE ATT&CK: G0010 View on attack.mitre.org

Aliases: IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, VENOMOUS Bear, WRAITH, Uroburos, Pfinet, TAG_0530, KRYPTON, Hippo Team, Pacifier APT, Popeye, SIG23, MAKERSMARK, ATK13, ITG12, Blue Python, SUMMIT, UNC4210, UAC-0144, UAC-0024, UAC-0003, Turla, ATG26

First seen
2004-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
449 (433 malicious)
Last IoC activity
2026-09-02 02:39:11
Profile updated
2026-07-07 12:34:09

Targeted industries: government-and-public-sector defense-and-aerospace education-and-nonprofits healthcare-and-pharmaceutical

Context

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.

Recent IoC activity

433 malicious indicators in Maltiverse are attributed to Turla (G0010). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.nullsecurity.net 2026-09-03 1
hostname ns-3.open.ro 2026-09-03 1
hostname autodiscover.email 2026-09-03 1
hostname autodiscover.exchange 2026-09-03 1
hostname autoconfig.email 2026-09-03 1
hostname mail.pics 2026-09-03 1
hostname prod.tools 2026-09-02 1
hostname webdisk.us 2026-09-02 1
hostname autodiscover.host 2026-09-02 1
hostname admin.dev 2026-09-02 1
hostname autodiscover.it 2026-09-02 1
hostname made.by 2026-09-02 1
hostname www.cantrip.org 2026-09-02 1
hostname test.support 2026-09-02 1
hostname mail.news 2026-09-02 1
hostname webdisk.it 2026-09-02 1
hostname webdisk.de 2026-09-02 1
hostname autodiscover.online 2026-09-02 1
hostname secure.dev 2026-09-02 1
hostname autodiscover.de 2026-09-02 1

Detection coverage

  • 34 YARA rules
  • 966 Sigma rules

Malware & tools used

  • Modify Registry (attack-pattern)
  • Local Groups (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Tool (attack-pattern)
  • JavaScript (attack-pattern)
  • Create Process with Token (attack-pattern)
  • Visual Basic (attack-pattern)
  • PowerShell Profile (attack-pattern)
  • Web Services (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Windows Credential Manager (attack-pattern)
  • Proxy (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Group Policy Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Mail Protocols (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Data from Local System (attack-pattern)
  • Query Registry (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Brute Force (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • blog.google — Continued Cyber Activity In Eastern Europe Observed By Tag (report)
  • blog.google — Fog Of War How The Ukraine Conflict Transformed The Cyber Threat Landscape (report)
  • cip.gov.ua — Download (report)
  • circl.lu — Tr 25 (report)
  • Kaspersky — 81638 (report)
  • Kaspersky — 65545 (report)
  • cfr.org — Turla (report)
  • nytimes.com — 26Cyber (report)
  • Kaspersky — The Penquin Turla 2 (report)
  • kaspersky.com — 6713 (report)
  • Mandiant — Rpt Witchcoven (report)
  • Kaspersky — The Epic Turla Operation (report)
  • threatpost.com — 109765 (report)
  • Kaspersky — 72081 (report)
  • ESET — Turla Mosquito Shift Towards Generic Tools (report)
  • first.org — Turla Operations And Development (report)
  • yle.fi — 8591548 (report)
  • ESET — Carbon Paper Peering Turlas Second Stage Backdoor (report)
  • Kaspersky — Satellite Turla Apt Command And Control In The Sky (report)
  • nccgroup.trust — Turla Png Dropper Is Back (report)
  • Broadcom/Symantec — Waterbug Attack Group (report)
  • theguardian.com — Turla Hackers Spying Governments Researcher Kaspersky Symantec (report)
  • bleepingcomputer.com — Turla Outlook Backdoor Uses Clever Tactics For Stealth And Persistence (report)

Attributed from

  • C0026 (campaign)

External references