← All Threat Actors
Threat Actor Profile

Turla

ATK13 BELUGASTURGEON Blue Python G0010 Group 88 Hippo Team IRON HUNTER ITG12 KRYPTON MAKERSMARK Pacifier APT Pensive Ursa Pfinet Popeye Secret Blizzard SIG23 Snake SUMMIT TAG_0530 TURLA RELIC UAC-0003 UAC-0024 UAC-0144 UNC4210 Uroburos VENOMOUS Bear Waterbug White Atlas WhiteBear Witchcoven WRAITH
⚠ Critical Threat
Post-Snake Infrastructure Adaptation, Edge Device Perimeter Breach, EU/NATO Diplomatic Intelligence Collection
Origin Russia
Sponsor Russian Federation (FSB)
Motivation Strategic intelligence gathering and political espionage

Target Sectors

Government agencies Diplomatic missions Defense industrial base Aerospace and Satellite communications NATO member states European Union institutions Research and academic institutions

Known TTPs

Exploitation of edge devices (VPNs, firewalls, routers)
Cloud-based C2 infrastructure (using legitimate cloud APIs to bypass security)
DLL side-loading for persistence
Use of custom modular implants (evolutions of Snake/Uroburos)
Living-off-the-Land (LotL) binaries to minimize footprint
Satellite link hijacking and manipulation
Highly obfuscated network protocols

External Resources

CISA Advisories ↗

Related Intelligence


LINK COPIED TO CLIPBOARD