
Turla is a Russia-linked advanced persistent threat (APT) group that has been active since at least 2008 and is widely assessed to conduct long-term cyber espionage operations in support of Russian strategic intelligence objectives. The threat actor is known for targeting government institutions, diplomatic entities, military organizations, and other high-value networks to obtain sensitive political, military, and strategic intelligence. The threat actor employs sophisticated malware, covert persistence mechanisms, and encrypted command-and-control (C2) infrastructure to maintain long-term access while minimizing detection. The group has demonstrated advanced operational security practices, including the use of custom toolsets, stealthy surveillance techniques, and encrypted communications, making attribution and analysis particularly challenging. The threat actor continues to refine its tradecraft and remains one of the most capable and persistent state-sponsored cyber espionage groups.
Alias: Group 88, Iron Hunter, Krypton, Sig23, Summit, Secret Blizzard, Snake, Turla, Turla Team, UAC-0194, Uroburos, Venomous Bear, Waterbug.
Motivation: Espionage
Targeted Industries:

Targeted Countries:
Belarus, France, Germany, India, Iran, Iraq, Italy, Kazakhstan, Netherlands, Poland, Romania, Russia, Russian Federation, Saudi Arabia, Switzerland, Tajikistan, Ukraine, United States, Uzbekistan.

Target Technologies:
Office Suites Software, Operating System, Web Applications, Windows.
Malware used by Turla Group:
Uroburos, Comrat, Epic, Stockstay Backdoor, Kazuar, Carbon, Wildday, Lightneuron, Apolloshadow, Mosquito, Diamondback, Powerstallion, Gazer, and Tinyturla-NG.

Turla continues to prioritize strategic cyber-espionage campaigns focused on intelligence collection rather than disruptive or destructive operations, demonstrating a sustained commitment to long-term access.
Continued Evolution of Malware Capabilities
The actor regularly enhances its malware ecosystem by introducing improved persistence mechanisms, defense-evasion techniques, encrypted communications, and modular functionality to maintain operational effectiveness.
Growing Emphasis on Stealth and Operational Security
Recent campaigns demonstrate increased use of living-off-the-land techniques, legitimate administrative utilities, fileless execution methods, and carefully managed command-and-control communications to reduce forensic visibility.
Expansion Across Strategic Sectors
While government and diplomatic organizations remain primary targets, Turla has also expanded its focus toward defense contractors, telecommunications providers, technology companies, research organizations, aerospace entities, and critical infrastructure.
Abuse of Trust Relationships and Legitimate Infrastructure
The group increasingly exploits trusted relationships, legitimate software, cloud platforms, and compromised infrastructure to facilitate covert access and minimize detection throughout the intrusion lifecycle.
Strategic Pre-Positioning within High-Value Networks
Rather than pursuing immediate objectives, Turla frequently establishes long-term footholds within strategically important environments, enabling continuous intelligence collection and rapid operational access when required.
| Tactic | ID | Technique |
| Resource Development | T1587.001 | Develop Capabilities: Malware |
| Resource Development | T1583.006 | Acquire Infrastructure: Web Services |
| Resource Development | T1584.003 | Compromise Infrastructure: Virtual Private Server |
| Resource Development | T1584.004 | Compromise Infrastructure: Server |
| Resource Development | T1584.006 | Compromise Infrastructure: Web Services |
| Resource Development | T1588.002 | Obtain Capabilities: Tool |
| Resource Development | T1588.001 | Obtain Capabilities: Malware |
| Initial Access | T1189 | Drive-by Compromise |
| Initial Access | T1078.003 | Valid Accounts: Local Accounts |
| Initial Access | T1566.002 | Phishing: Spearphishing Link |
| Execution | T1106 | Native API |
| Execution | T1204.001 | User Execution: Malicious Link |
| Execution | T1059.003 | Command and Scripting Interpreter: Windows Command Shell |
| Execution | T1059.006 | Command and Scripting Interpreter: Python |
| Execution | T1059.007 | Command and Scripting Interpreter: JavaScript |
| Execution | T1059.005 | Command and Scripting Interpreter: Visual Basic |
| Persistence | T1078.003 | Valid Accounts: Local Accounts |
| Persistence | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| Persistence | T1547.004 | Boot or Logon Autostart Execution: Winlogon Helper DLL |
| Persistence | T1112 | Modify Registry |
| Persistence | T1546.003 | Event Triggered Execution: Windows Management Instrumentation Event Subscription |
| Persistence | T1546.013 | Event Triggered Execution: PowerShell Profile |
| Privilege Escalation | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| Privilege Escalation | T1547.004 | Boot or Logon Autostart Execution: Winlogon Helper DLL |
| Privilege Escalation | T1078.003 | Valid Accounts: Local Accounts |
| Privilege Escalation | T1546.003 | Event Triggered Execution: Windows Management Instrumentation Event Subscription |
| Privilege Escalation | T1546.013 | Event Triggered Execution: PowerShell Profile |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| Privilege Escalation | T1055 | Process Injection |
| Privilege Escalation | T1055.001 | Process Injection: Dynamic-link Library Injection |
| Privilege Escalation | T1134.002 | Access Token Manipulation: Create Process with Token |
| Stealth | T1078.003 | Valid Accounts: Local Accounts |
| Stealth | T1134.002 | Access Token Manipulation: Create Process with Token |
| Stealth | T1140 | Deobfuscate/Decode Files or Information |
| Stealth | T1564.012 | Hide Artifacts: File/Path Exclusions |
| Stealth | T1036.005 | Masquerading: Match Legitimate Resource Name or Location |
| Stealth | T1055.001 | Process Injection: Dynamic-link Library Injection |
| Stealth | T1055 | Process Injection |
| Stealth | T1027.005 | Obfuscated Files or Information: Indicator Removal from Tools |
| Stealth | T1027.010 | Obfuscated Files or Information: Command Obfuscation |
| Stealth | T1027.011 | Obfuscated Files or Information: Fileless Storage |
| Defense Impairment | T1112 | Modify Registry |
| Defense Impairment | T1685 | Disable or Modify Tools |
| Defense Impairment | T1553.006 | Subvert Trust Controls: Code Signing Policy Modification |
| Credential Access | T1110 | Brute Force |
| Credential Access | T1555.004 | Credentials from Password Stores: Windows Credential Manager |
| Discovery | T1083 | File and Directory Discovery |
| Discovery | T1615 | Group Policy Discovery |
| Discovery | T1201 | Password Policy Discovery |
| Discovery | T1120 | Peripheral Device Discovery |
| Discovery | T1069.001 | Permission Groups Discovery: Local Groups |
| Discovery | T1069.002 | Permission Groups Discovery: Domain Groups |
| Discovery | T1057 | Process Discovery |
| Discovery | T1018 | Remote System Discovery |
| Discovery | T1087.001 | Account Discovery: Local Account |
| Discovery | T1087.002 | Account Discovery: Domain Account |
| Discovery | T1518.001 | Software Discovery: Security Software Discovery |
| Discovery | T1007 | System Service Discovery |
| Discovery | T1082 | System Information Discovery |
| Discovery | T1012 | Query Registry |
| Discovery | T1016 | System Network Configuration Discovery |
| Discovery | T1016.001 | System Network Configuration Discovery: Internet Connection Discovery |
| Discovery | T1049 | System Network Connections Discovery |
| Discovery | T1124 | System Time Discovery |
| Lateral Movement | T1021.002 | Remote Services: SMB/Windows Admin Shares |
| Lateral Movement | T1570 | Lateral Tool Transfer |
| Collection | T1213.006 | Data from Information Repositories: Databases |
| Collection | T1025 | Data from Removable Media |
| Collection | T1560.001 | Archive Collected Data: Archive via Utility |
| Collection | T1005 | Data from Local System |
| Command and Control | T1071.001 | Application Layer Protocol: Web Protocols |
| Command and Control | T1071.003 | Application Layer Protocol: Mail Protocols |
| Command and Control | T1090 | Proxy |
| Command and Control | T1090.001 | Proxy: Internal Proxy |
| Command and Control | T1105 | Ingress Tool Transfer |
| Command and Control | T1102 | Web Service |
| Command and Control | T1102.002 | Web Service: Bidirectional Communication |
| Exfiltration | T1567.002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage |