NEW: Group Profiler — instant APT intel lookup. Try it →

Turla

G0010 Russia Espionage MITRE ATT&CK →

Also known as: IRON HUNTER · Group 88 · Waterbug · WhiteBear · Snake · Krypton · Venomous Bear · Secret Blizzard · BELUGASTURGEON

Overview

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.

Naming & attribution

Turla is tracked under 10 names across the industry. It uses 68 documented ATT&CK techniques — more than 93% of the 174 groups tracked here. Activity attributed since at least 2004.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
IRON HUNTERSecureworks CTU
Group 88Leonardo
WaterbugSymantec
WhiteBearKaspersky Lab's Global Research & Analysis Team
SnakeMeyers, A
KryptonMeyers, A
Venomous BearMeyers, A
Secret BlizzardMicrosoft
BELUGASTURGEONAccenture
TurlaKaspersky Lab's Global Research and Analysis Team

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1546.013 PowerShell Profile — used by 1 of 174 groups
  • T1564.012 File/Path Exclusions — used by 1 of 174 groups
  • T1615 Group Policy Discovery — used by 1 of 174 groups
  • T1027.011 Fileless Storage — used by 2 of 174 groups
  • T1134.002 Create Process with Token — used by 2 of 174 groups
  • T1553.006 Code Signing Policy Modification — used by 2 of 174 groups
  • T1584.003 Virtual Private Server — used by 2 of 174 groups
  • T1201 Password Policy Discovery — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • APT32 Vietnam — 30 shared techniques (26% overlap)
  • OilRig Iran — 30 shared techniques (26% overlap)
  • MuddyWater Iran — 28 shared techniques (26% overlap)
  • Earth Lusca China — 23 shared techniques (26% overlap)
  • Gamaredon Group Russia — 28 shared techniques (25% overlap)
  • Volt Typhoon China — 29 shared techniques (24% overlap)

Malware families with current indicators

4 families attributed to Turla, carrying 7 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Kazuar 3 indicators
  • Gazer 2 indicators
  • ComRAT 1 indicators
  • KopiLuwak 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Education · Energy · Government · Healthcare · Military · Private sector

Regions

Belarus · France · Germany · India · Iran · Iraq · Kazakhstan · Netherlands · Poland · Romania · Russia · Saudi Arabia · South Korea · Tajikistan · United Kingdom · United States · Uzbekistan

Capabilities

  • Custom malware/implant development — ATT&CK: 17 attributed custom malware families

TTPs — 68 techniques across 13 tactics

Resource Development

Initial Access

Execution

Credential Access

Lateral Movement

Command and Control

Exfiltration

Tools & malware (30)

PsExec · nbtstat · ComRAT · netstat · certutil · Empire · Mosquito · KOPILUWAK · IronNetInjector · LunarWeb · Arp · Crutch · Uroburos · PowerStallion · Gazer · Kazuar · Systeminfo · LightNeuron · Carbon · Mimikatz · Tasklist · LunarMail · Net · Reg · HyperStack · Epic · NBTscan · TinyTurla · Penquin · LunarLoader

Reporting (3)