THREATOPS Actor Dossier
LIVE ← Dashboard

Turla

G00105 reports
aliases · Turla · IRON HUNTER · Group 88 · Waterbug · WhiteBear · Snake · Krypton · Venomous Bear · Secret Blizzard · BELUGASTURGEON
Export dossier:
5
Reports
12
Techniques
7
Tactics
9
Countries
53%
Hunt coverage
10
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1588.006 (Vulnerabilities), T1589.001 (Credentials), T1059.001 (PowerShell).
  • Primary targeting: RU, US, UA, BR.
  • Vulnerabilities exploited: 8 CVE(s) cited across multiple reports (e.g. CVE-2026-20245, CVE-2026-33017, CVE-2026-34908, CVE-2026-34909).
  • Currently dormant: 0 report(s) in last 30d vs 0 prior (+0%).
  • Hunt coverage 53% of 19 observed techniques (9 gap(s)).
  • Assessment confidence: medium (61).

Activity & trend

DormantLast 30d: 0 vs 0 prior (+0%)· first reported 2026-06-02 · last 2026-07-03
0
7d
0
30d
4
90d
5
All
0.3
Rpts/wk
Reporting timeline · 12 months

Vulnerabilities in this actor's reporting · 9

Overview

Analyst triage
Intelligence summary

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.(Citation: Kaspersky Turla)(Citation: ESET Gazer Aug 2017)(Citation: CrowdStrike VENOMOUS BEAR)(Citation: ESET Turla Mosquito Jan 2018)(Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected