Turla is a long-running Russian-linked espionage threat actor known for sustained intelligence collection against government, diplomatic, defense, and civil-society targets. The group is widely tracked under multiple names including Secret Blizzard, Pensive Ursa, Waterbug, and historically Snake/Uroburos-related designations. It has operated for well over a decade and is associated with a broad malware ecosystem that includes Kazuar, TinyTurla, ComRAT, Crutch, LightNeuron, Mosquito, Gazer, Uroburos, Penquin Turla, and other loaders, wrappers, and post-compromise tooling. Turla is characterized by persistent, adaptive tradecraft and long-term access operations. Reported activity includes targeted intrusions against diplomats, government entities, NGOs, and defense-sector organizations, particularly in Ukraine and Eastern Europe. The group has also been linked to campaigns against Polish NGOs and to operations involving adversary-in-the-middle techniques against diplomatic targets. Its tooling and operations span Windows, Linux, and macOS environments, and its malware development has included email- and Outlook-focused implants, Exchange-related access, web shells, watering-hole delivery, stealthy loaders, and specialized command-and-control approaches including satellite-based techniques. Operationally, Turla demonstrates strong capabilities across the intrusion lifecycle, including initial access, persistence, defense evasion, post-exploitation, and exfiltration. The actor has repeatedly evolved Kazuar and related malware families, used compromised third-party infrastructure, and in some cases leveraged or hijacked the tools or infrastructure of other threat groups to obscure attribution and expand victim access. Its activity is consistently aligned with strategic intelligence collection rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.