Turla is a long-running Russian state-linked espionage threat actor widely tracked under aliases including Secret Blizzard, Pensive Ursa, Waterbug, Snake, Uroburos, and Venomous Bear. The group has operated for well over a decade and is associated with a broad malware ecosystem that includes Kazuar, TinyTurla, ComRAT, Crutch, LightNeuron, Mosquito, Gazer, Snake, Uroburos, Carbon, HyperStack, IronNetInjector, CAPIBAR, Wipbot, FlyingYeti, and Penquin Turla. Turla is known for persistent intelligence collection against governments, diplomatic missions, defense-related entities, NGOs, and organizations connected to Ukraine and Eastern Europe. Operationally, Turla has demonstrated mature post-compromise tradecraft and long-term persistence. Reported techniques and tooling include custom loaders and wrappers, web shells, watering-hole operations, Outlook- and Exchange-focused implants, remote code execution through email-centric backdoors, multiplatform malware for Windows, Linux, and macOS, and covert command-and-control methods including satellite-based infrastructure. More recent reporting also links the actor to adversary-in-the-middle operations targeting diplomats and to campaigns in which it abused or compromised the infrastructure or tooling of other threat groups to support espionage objectives. Kazuar is one of the group’s most prominent backdoors and has remained a recurring component of Turla operations, including activity directed at diplomatic and defense-sector targets. TinyTurla and related implants have also been used in targeted espionage, including operations against Polish NGOs. Across its campaigns, Turla consistently exhibits reconnaissance, initial access, persistence, defense evasion, and post-exploitation capabilities in support of strategic intelligence collection. The actor’s dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.