Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON
68
techniques
30
software
11,801
corpus matches
profile
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.
techniques
68 attributed · most-instrumented first
software
30 malware & tools attributed
Mimikatz
S0002
Uroburos
S0022
PsExec
S0029
Net
S0039
Tasklist
S0057
Reg
S0075
Epic
S0091
Systeminfo
S0096
Arp
S0099
nbtstat
S0102
read this carefully
11,801 corpus matches is not attribution
That count is indicators which exhibit techniques Turla is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+56 more techniques
netstat
S0104
ComRAT
S0126
certutil
S0160
Gazer
S0168
Mosquito
S0256
Kazuar
S0265
Carbon
S0335
Empire
S0363
PowerStallion
S0393
LightNeuron
S0395
HyperStack
S0537
Crutch
S0538
IronNetInjector
S0581
Penquin
S0587
NBTscan
S0590
TinyTurla
S0668
KOPILUWAK
S1075
LunarWeb
S1141
LunarMail
S1142
LunarLoader
S1143
showing 30 of 11,801
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.