APT PROFILE – TURLA GROUP

Published On : 2026-08-13
Share :
APT PROFILE – TURLA GROUP

Turla is a Russia-linked advanced persistent threat (APT) group that has been active since at least 2008 and is widely assessed to conduct long-term cyber espionage operations in support of Russian strategic intelligence objectives. The threat actor is known for targeting government institutions, diplomatic entities, military organizations, and other high-value networks to obtain sensitive political, military, and strategic intelligence. The threat actor employs sophisticated malware, covert persistence mechanisms, and encrypted command-and-control (C2) infrastructure to maintain long-term access while minimizing detection. The group has demonstrated advanced operational security practices, including the use of custom toolsets, stealthy surveillance techniques, and encrypted communications, making attribution and analysis particularly challenging. The threat actor continues to refine its tradecraft and remains one of the most capable and persistent state-sponsored cyber espionage groups.

Alias: Group 88, Iron Hunter, Krypton, Sig23, Summit, Secret Blizzard, Snake, Turla, Turla Team, UAC-0194, Uroburos, Venomous Bear, Waterbug.

Motivation: Espionage

Targeted Industries:

Targeted Countries:
Belarus, France, Germany, India, Iran, Iraq, Italy, Kazakhstan, Netherlands, Poland, Romania, Russia, Russian Federation, Saudi Arabia, Switzerland, Tajikistan, Ukraine, United States, Uzbekistan.

Target Technologies:
Office Suites Software, Operating System, Web Applications, Windows.

Malware used by Turla Group:
Uroburos, Comrat, Epic, Stockstay Backdoor, Kazuar, Carbon, Wildday, Lightneuron, Apolloshadow, Mosquito, Diamondback, Powerstallion, Gazer, and Tinyturla-NG.

ATTACK FLOW DIAGRAM OF APT THREAT ACTOR TURLA GROUP

Turla Group’s Recent Campaign Highlights and Trends

Recent Campaign Highlights

  • April–June 2026 – Expansion Across Strategic Technology and Enterprise Environments: The CYFIRMA Research team identified Turla as a Russia-linked cyber-espionage group targeting government, diplomatic, defence, research, and technology organizations. The group’s activities involved attempts to compromise email and communication systems, enterprise networks, VPN and proxy infrastructure, operating systems, web applications, and other internet-facing technologies. This activity highlights Turla’s continued focus on gaining access to organizations that hold sensitive or strategically valuable information.
  • July 2026 – STOCKSTAY Backdoor Activity: CYFIRMA reported Turla’s suspected use of the STOCKSTAY backdoor against government organizations, Western foreign ministries, and defence entities in Ukraine and Italy. The campaign appeared to be primarily focused on cyber-espionage and intelligence collection, with the attackers seeking to maintain long-term access to compromised networks and gather sensitive information.
  • July 2026 – French Entities Targeted Using the Turla Intrusion Set: In July 2026, researchers reported a Turla intrusion campaign targeting and compromising French organizations. The affected entities included organizations and ministries associated with the diplomatic, defence, justice, and technology sectors. The activity demonstrates Turla’s continued interest in European organizations, particularly those involved in government operations, national security, and strategic technologies.

Trends

Expansion of Long-Term Cyber-Espionage Operations

Turla continues to prioritize strategic cyber-espionage campaigns focused on intelligence collection rather than disruptive or destructive operations, demonstrating a sustained commitment to long-term access.

Continued Evolution of Malware Capabilities
The actor regularly enhances its malware ecosystem by introducing improved persistence mechanisms, defense-evasion techniques, encrypted communications, and modular functionality to maintain operational effectiveness.

Growing Emphasis on Stealth and Operational Security
Recent campaigns demonstrate increased use of living-off-the-land techniques, legitimate administrative utilities, fileless execution methods, and carefully managed command-and-control communications to reduce forensic visibility.

Expansion Across Strategic Sectors
While government and diplomatic organizations remain primary targets, Turla has also expanded its focus toward defense contractors, telecommunications providers, technology companies, research organizations, aerospace entities, and critical infrastructure.

Abuse of Trust Relationships and Legitimate Infrastructure
The group increasingly exploits trusted relationships, legitimate software, cloud platforms, and compromised infrastructure to facilitate covert access and minimize detection throughout the intrusion lifecycle.

Strategic Pre-Positioning within High-Value Networks
Rather than pursuing immediate objectives, Turla frequently establishes long-term footholds within strategically important environments, enabling continuous intelligence collection and rapid operational access when required.

TTPs based on MITRE ATT&CK Framework

Tactic ID Technique
Resource Development T1587.001 Develop Capabilities: Malware
Resource Development T1583.006 Acquire Infrastructure: Web Services
Resource Development T1584.003 Compromise Infrastructure: Virtual Private Server
Resource Development T1584.004 Compromise Infrastructure: Server
Resource Development T1584.006 Compromise Infrastructure: Web Services
Resource Development T1588.002 Obtain Capabilities: Tool
Resource Development T1588.001 Obtain Capabilities: Malware
Initial Access T1189 Drive-by Compromise
Initial Access T1078.003 Valid Accounts: Local Accounts
Initial Access T1566.002 Phishing: Spearphishing Link
Execution T1106 Native API
Execution T1204.001 User Execution: Malicious Link
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell
Execution T1059.006 Command and Scripting Interpreter: Python
Execution T1059.007 Command and Scripting Interpreter: JavaScript
Execution T1059.005 Command and Scripting Interpreter: Visual Basic
Persistence T1078.003 Valid Accounts: Local Accounts
Persistence T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Persistence T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL
Persistence T1112 Modify Registry
Persistence T1546.003 Event Triggered Execution: Windows Management Instrumentation Event Subscription
Persistence T1546.013 Event Triggered Execution: PowerShell Profile
Privilege Escalation T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL
Privilege Escalation T1078.003 Valid Accounts: Local Accounts
Privilege Escalation T1546.003 Event Triggered Execution: Windows Management Instrumentation Event Subscription
Privilege Escalation T1546.013 Event Triggered Execution: PowerShell Profile
Privilege Escalation T1068 Exploitation for Privilege Escalation
Privilege Escalation T1055 Process Injection
Privilege Escalation T1055.001 Process Injection: Dynamic-link Library Injection
Privilege Escalation T1134.002 Access Token Manipulation: Create Process with Token
Stealth T1078.003 Valid Accounts: Local Accounts
Stealth T1134.002 Access Token Manipulation: Create Process with Token
Stealth T1140 Deobfuscate/Decode Files or Information
Stealth T1564.012 Hide Artifacts: File/Path Exclusions
Stealth T1036.005 Masquerading: Match Legitimate Resource Name or Location
Stealth T1055.001 Process Injection: Dynamic-link Library Injection
Stealth T1055 Process Injection
Stealth T1027.005 Obfuscated Files or Information: Indicator Removal from Tools
Stealth T1027.010 Obfuscated Files or Information: Command Obfuscation
Stealth T1027.011 Obfuscated Files or Information: Fileless Storage
Defense Impairment T1112 Modify Registry
Defense Impairment T1685 Disable or Modify Tools
Defense Impairment T1553.006 Subvert Trust Controls: Code Signing Policy Modification
Credential Access T1110 Brute Force
Credential Access T1555.004 Credentials from Password Stores: Windows Credential Manager
Discovery T1083 File and Directory Discovery
Discovery T1615 Group Policy Discovery
Discovery T1201 Password Policy Discovery
Discovery T1120 Peripheral Device Discovery
Discovery T1069.001 Permission Groups Discovery: Local Groups
Discovery T1069.002 Permission Groups Discovery: Domain Groups
Discovery T1057 Process Discovery
Discovery T1018 Remote System Discovery
Discovery T1087.001 Account Discovery: Local Account
Discovery T1087.002 Account Discovery: Domain Account
Discovery T1518.001 Software Discovery: Security Software Discovery
Discovery T1007 System Service Discovery
Discovery T1082 System Information Discovery
Discovery T1012 Query Registry
Discovery T1016 System Network Configuration Discovery
Discovery T1016.001 System Network Configuration Discovery: Internet Connection Discovery
Discovery T1049 System Network Connections Discovery
Discovery T1124 System Time Discovery
Lateral Movement T1021.002 Remote Services: SMB/Windows Admin Shares
Lateral Movement T1570 Lateral Tool Transfer
Collection T1213.006 Data from Information Repositories: Databases
Collection T1025 Data from Removable Media
Collection T1560.001 Archive Collected Data: Archive via Utility
Collection T1005 Data from Local System
Command and Control T1071.001 Application Layer Protocol: Web Protocols
Command and Control T1071.003 Application Layer Protocol: Mail Protocols
Command and Control T1090 Proxy
Command and Control T1090.001 Proxy: Internal Proxy
Command and Control T1105 Ingress Tool Transfer
Command and Control T1102 Web Service
Command and Control T1102.002 Web Service: Bidirectional Communication
Exfiltration T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage