Turla is a long-running Russian state-linked cyber-espionage threat actor widely tracked under aliases including Snake, Uroburos, Waterbug, Venomous Bear, WhiteBear, Secret Blizzard, Pensive Ursa, Krypton, Iron Hunter, Group 88, and Turla APT. The group is known for sustained intelligence collection operations against government, military, diplomatic, research, education, and pharmaceutical targets across dozens of countries. Turla is notable for developing and operating custom malware and backdoors, including the Snake/Uroburos platform, and for maintaining a mature post-compromise tradecraft focused on stealth, persistence, and long-term access. Reported behaviors include spearphishing with malicious attachments for initial access; extensive host and network reconnaissance using native commands; command execution through cmd and PowerShell; in-memory payload execution; encrypted payload storage in the Windows Registry; file upload and exfiltration capabilities through RPC-style backdoors; and use of custom decryption routines to recover protected PowerShell payloads. The group has also used VBScript and other scripting components during operations. Turla has demonstrated advanced operational security and infrastructure tradecraft. It has used compromised servers as operational infrastructure and is especially known for abusing satellite communications to help conceal command-and-control and exfiltration activity by relaying traffic through legitimate satellite network users. The group has also been reported to repurpose malware obtained from other threat actors, including tooling associated with OilRig. Turla’s activity is consistent with strategic espionage rather than financially motivated intrusion. Its targeting, malware development, and persistence-focused operations align with a highly capable intelligence-oriented actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
46 malware families attributed to this actor across reporting.
41 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
That campaign used malicious RAR archives exploiting a WinRAR path traversal flaw tracked as CVE-2025-8088.
The Java files exploit a popular vulnerability, CVE-2012-1723, in various configurations.
CVE-2013-3346 – Arbitrary code-execution vulnerability in Adobe Reader
The attacks are known to have used at least two zero-day exploits: CVE-2013-5065 – Privilege escalation vulnerability in Windows XP and Windows 2003
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
4 more CVEs tied to this actor tracked in Mallory.
533 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian threat actor discussed in the context of cyber operations supporting Russia’s actions against Ukraine, including use of Snake and Uroburos against Ukrainian government systems.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Referenced as a comparison point for attacks on diplomatic entities and foreign ministries via peripheral systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.