Turla is a long-running Russian state-sponsored cyber espionage threat actor widely attributed to the 16th Centre of the Federal Security Service of the Russian Federation (FSB). Active since at least the early 2000s, and often assessed as operating since the late 1990s, Turla is known for persistent, covert intelligence collection against high-value government, diplomatic, military, defense-industrial, justice, technology, and critical-sector targets. Public reporting and official European attributions have linked the group to sustained operations across Europe, Ukraine, NATO member states, and other strategic regions. Turla is tracked under numerous aliases, including Snake, Uroburos, Waterbug, Venomous Bear, Secret Blizzard, Pensive Ursa, WhiteBear, Krypton, Iron Hunter, Blue Python, BelugaSturgeon, ATG26, Group 88, Wraith, and UAC-0003. Some names are used for the broader intrusion set, while others refer to specific malware families, campaign clusters, or vendor-specific tracking designations associated with the same operational ecosystem. The group specializes in long-term access, stealthy surveillance, and strategic intelligence gathering. Its victimology consistently centers on ministries, foreign affairs institutions, embassies, defense organizations, military entities, judicial and justice-sector bodies, telecommunications, research organizations, and technology companies. Turla has also used less strategic organizations and individuals as intermediaries or relay nodes to obscure operations and support follow-on targeting. Turla’s tradecraft includes spearphishing, watering-hole compromises, exploitation of internet-facing systems, abuse of trusted communications, credential theft, covert persistence on compromised infrastructure, and the compromise of routers and other network devices for operational concealment and durable access. The group has demonstrated cross-platform capability against Windows, Linux, and macOS environments, and has targeted servers, email systems, browsers, and enterprise applications. It is also associated with living-off-the-land techniques and the use of both bespoke malware and publicly available post-exploitation tooling. Malware and tooling associated with Turla include Snake/Uroburos, Kazuar, and STOCKSTAY, among others. Snake has been described by Western authorities as one of the most sophisticated espionage implants attributed to FSB Centre 16. Turla has also been observed using persistence mechanisms such as Registry Run keys and Startup-folder execution, as well as techniques mapped to process injection and privilege escalation. Reporting has additionally linked the group to multi-component backdoors designed for long-term surveillance of diplomatic and government targets. Operationally, Turla is best characterized as a strategic espionage actor rather than a financially motivated or primarily destructive one. Its campaigns emphasize persistence, clandestine collection, and maintenance of access over extended periods. Recent public reporting and official statements have tied Turla activity to continued espionage against Ukrainian and European diplomatic organizations during Russia’s war against Ukraine, and European governments have publicly identified the group as part of a broader Russian cyber ecosystem combining intelligence services, proxy actors, and supporting infrastructure. France, the European Union, the United Kingdom, and other Western authorities have publicly attributed Turla-linked activity to the FSB’s 16th Centre and described years of targeting against European government networks and critical sectors. These attributions place Turla among the most prominent Russian intelligence-linked cyber espionage groups, notable for technical sophistication, operational longevity, and sustained focus on strategic state objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
55 malware families attributed to this actor across reporting.
50 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
That campaign used malicious RAR archives exploiting a WinRAR path traversal flaw tracked as CVE-2025-8088.
The Java files exploit a popular vulnerability, CVE-2012-1723, in various configurations.
CVE-2013-3346 – Arbitrary code-execution vulnerability in Adobe Reader
The attacks are known to have used at least two zero-day exploits: CVE-2013-5065 – Privilege escalation vulnerability in Windows XP and Windows 2003
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
3 more CVEs tied to this actor tracked in Mallory.
281 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FSB-attributed Russian APT specializing in long-term operations and covert persistence.
Conducts strategic cyberespionage, covert access, communications exploitation, and long-term surveillance against government, diplomatic, military, research, and media targets to achieve information superiority.
A notorious hacking collective described here as being orchestrated by the FSB's 16th Center as part of a decade-long cyber-espionage and attempted sabotage campaign targeting critical infrastructure and government networks across Europe.
State-sponsored cyber threat group described as part of Russia’s malicious cyber ecosystem targeting the EU, EU member states, and international partners including Ukraine, with activity tied to cyberespionage and broader disruptive operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.