Skip to main content
QUIETLYTIC
Threat Actor

Turla

Cyber espionage group attributed by MITRE ATT&CK to Russia's Federal Security Service (FSB), active since at least 2004 with victims in over 50 countries.

Threat Level
CRITICAL
Attribution
Russian Federal Security Service (FSB) — per MITRE ATT&CK's group profile, citing joint cybersecurity advisory AA23-129A
Also Known As
IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON
Targets
Government, embassies, and military, Education and research institutions, Pharmaceutical companies

Overview

Turla (MITRE ATT&CK ID G0010) is a cyber espionage threat group MITRE ATT&CK attributes to Russia’s Federal Security Service (FSB), citing the May 2023 joint cybersecurity advisory AA23-129A on “Snake” malware. Per MITRE’s profile, the group has compromised victims in over 50 countries since at least 2004, spanning government, embassies, military, education, research, and pharmaceutical sectors. MITRE documents Turla as known for watering-hole and spearphishing campaigns, leveraging in-house tools such as Uroburos.

Known tools and malware (per MITRE ATT&CK relationship data)

Our ingested data links Turla to a long-running, distinctively named custom toolset: Uroburos, Kazuar, ComRAT, Carbon, Crutch, HyperStack, TinyTurla, Gazer, Mosquito, LightNeuron, PowerStallion, KOPILUWAK, IronNetInjector, Penquin, and the LunarWeb/LunarMail/LunarLoader family — alongside dual-use tools Mimikatz, PsExec, Empire, and certutil.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques linked to Turla in our data include Archive via Utility (T1560.001), Bidirectional Communication (T1102.002), Brute Force (T1110), Code Signing Policy Modification (T1553.006), Command Obfuscation (T1027.010), and Create Process with Token (T1134.002).

What we don’t have

MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2004” per MITRE’s description text, making Turla one of the longest-documented groups in MITRE’s knowledge base by that measure. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no campaign relationships are present for this group in our ingested data.

Frequently Asked Questions

What is Turla? A cyber espionage group attributed by MITRE ATT&CK to Russia’s FSB, active since at least 2004 with documented victims in over 50 countries.

What is Turla’s best-known malware? Per MITRE ATT&CK’s description, Uroburos is the group’s flagship in-house tool; its relationship data also links Turla to Kazuar, ComRAT, and the Snake malware referenced in the FSB attribution advisory.

How long has Turla been active? Per MITRE ATT&CK’s profile, at least since 2004 — among the longest documented activity claims of any group in MITRE’s knowledge base.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0010, aggregated September 4, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools