Home/Threat Actor/Turla
Threat Actor

Turla

turla · russia · active since 2004

Turla (Snake / Uroburos / Venomous Bear / Pensive Ursa / Secret Blizzard / Waterbug / WhiteBear / Krypton / IRON HUNTER / Group 88 / BELUGASTURGEON / G0010) is a Russian FSB Center 16 cyber- espionage actor active since at least 2004, one of the oldest and most technically sophisticated state actors in public record , responsible for the 2008 Agent.BTZ infection of US Department of Defense networks, the Snake/Uroburos kernel rootkit ecosystem, pioneering satellite-based C2, the 2019 hijacking of Iranian APT34 infrastructure as a false-flag layer, the 2020 Crutch targeting of EU foreign-affairs ministries, the 2021 TinyTurla backdoor, the 2023 Capibar / Kazuar v3 targeting of Ukrainian defense organizations, the 2024 LunarWeb / LunarMail / LunarLoader campaign against European diplomatic missions, and the decade-spanning ComRAT lineage tracing back to Agent.BTZ, formally attributed to FSB Center 16 in Ryazan by US DOJ court documents filed in connection with the May 2023 Operation MEDUSA disruption of the Snake malware network.

russia confidence: high 28 aliases MITRE ATT&CK G0010 ↗

Profile

Turla is a Russian state-sponsored cyber-espionage actor attributed to the Federal Security Service (FSB), specifically Center 16, the FSB's signals intelligence directorate whose lineage traces back to former FAPSI (the Soviet/Russian equivalent of NSA/GCHQ). Active since at least 2004, Turla has compromised victims in more than 50 countries spanning government, diplomatic, military, research, education, pharmaceutical, and media sectors. The May 2023 US Department of Justice court documents associated with Operation MEDUSA formally named Center 16 as the Snake malware's operator and identified the FSB facility in Ryazan from which operations were conducted, one of the most specific and detailed public US government attributions to date. Turla is widely regarded as one of the most technically sophisticated state actors in the public record, distinguished by: (a) the Snake/Uroburos kernel-mode rootkit ecosystem and its peer-to-peer C2 network, an in-house family that has been continuously evolved for nearly two decades.

(b) pioneering and unusual C2 channels including hijacked satellite downlinks for passive reception of attacker commands.

(c) deep abuse of legitimate web services (Gmail, Dropbox, GitHub, Pastebin, OneDrive, Google Apps Script, WordPress) for C2 and exfiltration.

(d) the LightNeuron Exchange transport-agent backdoor that intercepts and manipulates email in transit.

(e) cross-platform reach including Linux (Penquin), macOS (Snake), and Windows kernel.

(f) the 2019 public exposure of Turla actively hijacking Iranian APT34/OilRig infrastructure, the first openly documented case of a state actor using another state actor's compromised assets as a false-flag layer.

and (g) sustained tradecraft refinement reflected in the lineage Agent.

BTZ (2008)
  • ComRAT v1-v4 (2008-2020)
  • newer modular tooling including TinyTurla, TinyTurla-NG, Capibar / DeliveryCheck, KOPILUWAK resurfacing, IronNetInjector / IronPython, and the 2024 LunarWeb / LunarMail / LunarLoader trio targeting European diplomatic missions. Turla's playbook is patient long-dwell collection rather than destruction or near-term influence operations. Victim presence is often measured in years; targeting consistently aligns with FSB foreign-intelligence collection priorities (NATO governments, foreign ministries, defense, dissidents, journalists, research) rather than the disruptive mission of GRU Unit 74455 / Sandworm or the broader influence-and-collection mission of GRU Unit 26165 / APT28. Microsoft tracks Turla as Secret Blizzard.

Aliases

28
turlairon huntergroup 88waterbugwhitebearwhite bearsnakekryptonvenomous bearsecret blizzardbelugasturgeonbeluga sturgeonuroburosuroborosouroborospensive ursablue pythonmakersmarkturla teamturla aptagent.btzagent btzmoonlight mazemoonlight_mazefsb center 16center 16fapsig0010

Notable Campaigns

14
2024LunarWeb / LunarMail Against European Ministry of Foreign Affairs (2024)
2023MITRE Engenuity ATT&CK Evaluation, Turla Round (2023)
2023Operation MEDUSA, Snake Malware Network Disruption (May 2023)
2023Capibar and Kazuar Against Ukrainian Defense (2023)
2021TinyTurla Backdoor Discovery (2021)
2021Post-SolarWinds Tomiris / Kazuar Code Overlap
2020Crutch, EU Government Targeting (2020)
2019Hijacking of Iranian APT34 / OilRig Infrastructure
2018Outlook Backdoor, Targeting Foreign Ministries (2018)
2017-2018German Foreign Office / Bundestag Network Compromise
2015Satellite-Based Command and Control (2015)
2014-2016Swiss RUAG Defense Contractor Compromise
2014Epic Turla Operation (Disclosed August 2014)
2008Agent.BTZ, US Department of Defense Compromise (2008)

Attribution & Reporting

Attributed by
FBIUS Department of JusticeCISANSAUS Cyber CommandUK NCSCUK GCHQCanadian Centre for Cyber Security (CCCS)Australian Signals Directorate (ASD)Australian Cyber Security Centre (ACSC)New Zealand NCSCFive EyesMicrosoftMandiantGoogle Cloud Threat IntelligenceGoogle Threat Analysis GroupCrowdStrikeKasperskySymantec / BroadcomESETCisco TalosPalo Alto Networks Unit 42SentinelOneSecureworksAccentureRecorded FutureInsikt GroupLeonardoIntel 471Booz Allen HamiltonThreatminer
Key reporting
reportKaspersky GReAT: The Epic Turla Operation, Solving Some of the Mysteries of Snake/Uroburos (August 2014)
reportKaspersky GReAT: Satellite Turla, APT Command and Control in the Sky (September 2015)
reportKaspersky: Introducing WhiteBear (August 2017)
reportKaspersky / Insikt: Sunburst, Tomiris, and Kazuar, Connecting the Dots (September 2021)
reportESET: Carbon Paper, Peering into Turla's Second-Stage Backdoor (March 2017)
reportESET: Gazing at Gazer, Turla's New Second-Stage Backdoor (August 2017)
reportESET: Diplomats in Eastern Europe Bitten by a Turla Mosquito (January 2018)
reportESET: Turla Mosquito, A Shift Toward More Generic Tools (May 2018)
reportESET: Turla Outlook Backdoor, Analysis of an Unusual Turla Backdoor (August 2018)
reportESET: LightNeuron, A Microsoft Exchange Transport Agent Backdoor (May 2019)
reportESET: Turla LightNeuron, One Email Away from Remote Code Execution (May 2019)
reportESET: A Dive into Turla PowerShell Usage (May 2019)
reportESET: From Agent.BTZ to ComRAT v4, A Ten-Year Journey (May 2020)
reportESET: Turla Crutch, Keeping the Back Door Open (December 2020)
reportESET: Moon Backdoors and Lunar Landing in Diplomatic Missions (May 2024)
reportCrowdStrike: Adversary of the Month, VENOMOUS BEAR (March 2018)
reportSymantec / Broadcom: Waterbug, Espionage Hacking Group Adopts New Tools (June 2019)
reportAccenture: Turla / BelugaSturgeon Compromises Government Entity (November 2020)
reportCisco Talos: TinyTurla, A New Stealthy Backdoor (September 2021)
reportCisco Talos: TinyTurla-NG (January 2024)
reportMandiant: Turla Galaxy Opportunity, KOPILUWAK Resurfaces (January 2023)
reportPalo Alto Networks Unit 42: IronNetInjector, Turla's New Malware Loading Tool (February 2021)
reportPalo Alto Networks Unit 42: AcidBox, Rare Malware Repurposing Turla Group Exploit (June 2020)
reportPalo Alto Networks Unit 42: Kazuar, Multiplatform Espionage Backdoor with API Access (May 2017)
reportPalo Alto Networks Unit 42 (Pensive Ursa Assessment): Threat Group Assessment (2023)
reportRecorded Future / Insikt Group: Swallowing the Snake's Tail, Tracking Turla Infrastructure (March 2020)
reportLeonardo: Malware Technical Insight, Turla Penquin_x64
reportNSA / NCSC UK: Turla Group Exploits Iranian APT to Expand Coverage of Victims (October 2019)
reportCISA AA23-129A: Hunting Russian Intelligence 'Snake' Malware (May 2023)
reportUS DOJ: Court-Authorized Disruption of Snake Malware Network (Operation MEDUSA, May 2023)
reportMITRE Engenuity: 2023 ATT&CK Evaluations, Turla Emulation Round (September 2023)
reportEuRepoC: APT Profile, Turla
reportIntel 471: Threat Hunting Case Study, Uncovering Turla (August 2025)

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)50/60 · 83%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)4/60 · 6%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)10/60 · 16%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin