FORENSIA

THREAT_ACTOR · G0010

Turla

Also known as: Turla, IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON

Profile

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.

MITRE ATT&CK ↗

Techniques

68 ATT&CK techniques attributed to this actor.

T1005 Data from Local SystemT1007 System Service DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1016.001 Internet Connection DiscoveryT1018 Remote System DiscoveryT1021.002 SMB/Windows Admin SharesT1025 Data from Removable MediaT1027.005 Indicator Removal from ToolsT1027.010 Command ObfuscationT1027.011 Fileless StorageT1036.005 Match Legitimate Resource Name or LocationT1049 System Network Connections DiscoveryT1055 Process InjectionT1055.001 Dynamic-link Library InjectionT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.006 PythonT1059.007 JavaScriptT1068 Exploitation for Privilege EscalationT1069.001 Local GroupsT1069.002 Domain GroupsT1071.001 Web ProtocolsT1071.003 Mail ProtocolsT1078.003 Local AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1090 ProxyT1090.001 Internal ProxyT1102 Web ServiceT1102.002 Bidirectional CommunicationT1105 Ingress Tool TransferT1106 Native APIT1110 Brute ForceT1112 Modify RegistryT1120 Peripheral Device DiscoveryT1124 System Time DiscoveryT1134.002 Create Process with TokenT1140 Deobfuscate/Decode Files or InformationT1189 Drive-by CompromiseT1201 Password Policy DiscoveryT1204.001 Malicious LinkT1213.006 DatabasesT1518.001 Security Software DiscoveryT1546.003 Windows Management Instrumentation Event SubscriptionT1546.013 PowerShell ProfileT1547.001 Registry Run Keys / Startup FolderT1547.004 Winlogon Helper DLLT1553.006 Code Signing Policy ModificationT1555.004 Windows Credential ManagerT1560.001 Archive via UtilityT1564.012 File/Path ExclusionsT1566.002 Spearphishing LinkT1567.002 Exfiltration to Cloud StorageT1570 Lateral Tool TransferT1583.006 Web ServicesT1584.003 Virtual Private ServerT1584.004 ServerT1584.006 Web ServicesT1587.001 MalwareT1588.001 MalwareT1588.002 ToolT1615 Group Policy DiscoveryT1685 Disable or Modify Tools

Software

30 malware/tools attributed to this actor.

MimikatzUroburosPsExecNetTasklistRegEpicSysteminfoArpnbtstatnetstatComRATcertutilGazerMosquitoKazuarCarbonEmpirePowerStallionLightNeuronHyperStackCrutchIronNetInjectorPenquinNBTscanTinyTurlaKOPILUWAKLunarWebLunarMailLunarLoader

Related corpus activity

10,455 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Turla.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,455.