Turla is a long-running Russian state-linked espionage threat actor widely tracked under aliases including Secret Blizzard, Pensive Ursa, Waterbug, Snake, Uroburos, and Venomous Bear. It is associated with Russian intelligence operations and is known for sustained cyber-espionage campaigns against government, diplomatic, defense, and civil-society targets, particularly in Europe and in matters connected to Ukraine and Eastern Europe. The group has operated for well over a decade and is notable for maintaining a large and evolving malware ecosystem rather than relying on a single toolset. Turla has been linked to malware and intrusion sets including Kazuar, TinyTurla, ComRAT, Crutch, LightNeuron, Mosquito, Gazer, Uroburos, Penquin Turla, Carbon, CAPIBAR, Wipbot, FlyingYeti, and other loaders, wrappers, and web-shell components. Its operations have included Outlook- and Exchange-focused implants, multiplatform backdoors for Windows, Linux, and macOS, and specialized command-and-control approaches including satellite-based techniques. Reporting has also tied the actor to watering-hole operations, adversary-in-the-middle activity targeting diplomats, compromise of third-party infrastructure, and the use of other groups’ tools or infrastructure to obscure attribution and expand victim access. Observed tradecraft includes targeted initial access, long-term persistence, credential and data theft, post-exploitation, defense evasion, and reconnaissance. Turla has repeatedly deployed custom loaders and malware staging mechanisms, including wrapper and injector components, to deliver or refresh implants such as Kazuar and TinyTurla. The actor is also known for covert collection from email systems and for maintaining durable access to high-value networks over extended periods. Its activity is consistently characterized as espionage-focused rather than financially motivated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.