Turla is a long-running Russian state-linked espionage threat actor widely tracked under aliases including Secret Blizzard, Pensive Ursa, Waterbug, Snake, Uroburos, and Venomous Bear. It is associated with a broad malware ecosystem that includes Kazuar, TinyTurla, ComRAT, Crutch, LightNeuron, Mosquito, Gazer, Uroburos, Penquin Turla, CAPIBAR, Wipbot, FlyingYeti, ApolloShadow, and related loaders and wrappers. The group has conducted sustained intelligence collection operations over many years against governments, diplomatic missions, defense-related entities, NGOs, and organizations connected to Ukraine and Eastern Europe. Turla is known for stealthy, persistent post-compromise tradecraft and continual tooling evolution. Reported capabilities include long-term persistence, post-exploitation, credentialed access support, defense evasion, and exfiltration through custom backdoors, loaders, web shells, email- and Outlook-focused implants, Exchange-oriented tooling, and multiplatform malware for Windows, Linux, and macOS. Public reporting has also linked the actor to watering-hole operations, adversary-in-the-middle activity against diplomats, abuse of compromised third-party infrastructure, and unusual command-and-control approaches including satellite-based techniques. The group has repeatedly refreshed its malware families and delivery mechanisms, including newer Kazuar variants and TinyTurla tooling, while also leveraging other groups’ tools or infrastructure to obscure attribution and expand victim access. Recent activity has included espionage operations targeting diplomats, Polish NGOs, and Ukrainian defense-sector organizations, as well as broader campaigns against government and public-sector entities. Turla is best characterized as a mature, highly capable cyber-espionage actor aligned with Russian intelligence objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.