Turla
G00105 reportsAnalyst assessment — key judgments
- Signature techniques: T1588.006 (Vulnerabilities), T1589.001 (Credentials), T1059.001 (PowerShell).
- Primary targeting: RU, US, UA, BR.
- Vulnerabilities exploited: 8 CVE(s) cited across multiple reports (e.g. CVE-2026-20245, CVE-2026-33017, CVE-2026-34908, CVE-2026-34909).
- Currently dormant: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 53% of 19 observed techniques (9 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
Vulnerabilities in this actor's reporting · 9
- CVE-2026-20245KEV2 rpt
- CVE-2026-33017KEV2 rpt
- CVE-2026-34908KEV2 rpt
- CVE-2026-34909KEV2 rpt
- CVE-2026-34910KEV2 rpt
- CVE-2026-55255KEV2 rpt
- CVE-2026-419472 rpt
- CVE-2026-419482 rpt
- CVE-2025-8088KEV1 rpt
Overview
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.(Citation: Kaspersky Turla)(Citation: ESET Gazer Aug 2017)(Citation: CrowdStrike VENOMOUS BEAR)(Citation: ESET Turla Mosquito Jan 2018)(Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023)
ATT&CK technique matrix
- T1588.006 · Vulnerabilitiesconf 653
- T1589.001 · Credentialsconf 653
- T1059.001 · PowerShellconf 652
- T1059.007 · JavaScriptconf 652
- T1053.005 · Scheduled Taskconf 601
- T1204.002 · Malicious Fileconf 601
- T1684 · Social Engineeringconf 601evidence: 22nd June – Threat Intelligence Report
- T1589.002 · Email Addressesconf 601evidence: 29th June – Threat Intelligence Report
- T1047 · Windows Management Instrumentationconf 601
- T1574.014 · AppDomainManagerconf 601
- T1036 · Masqueradingconf 601
- T1087.003 · Email Accountconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|