Turla is a long-running, highly sophisticated cyber-espionage malware platform and associated intrusion ecosystem, also widely known as Snake and Uroburos. It has been active since at least the mid-2000s and is broadly assessed by multiple security vendors and government reporting as linked to Russia’s FSB, commonly Center 16. Turla has primarily targeted diplomatic, government, military, research, and other high-value organizations across Europe, the Middle East, Asia, the former Soviet sphere, and elsewhere, with operations focused on long-term intelligence collection.
Turla is best understood as a modular intrusion framework rather than a single implant. Reported components and related tooling include Epic Turla as an initial-stage foothold, Carbon as a more advanced backdoor platform, LightNeuron targeting Microsoft Exchange environments, Penquin for Linux, and Kazuar in later operations. The malware family has been described as using rootkit and stealth techniques, encrypted or hidden storage, virtual file systems, and resilient command-and-control designs. Documented capabilities include remote command execution, remote management, credential theft in some intrusion chains, keylogging, lateral movement, persistence, exfiltration, and defense evasion. Turla operators have also used internal relay nodes or “communication drones” to route traffic through victim networks and maintain covert access.
Initial access associated with Turla has included spearphishing and watering-hole compromises. The Epic Turla intrusion chain used malicious documents, social engineering lures, and exploit-driven delivery, including exploitation of CVE-2013-3346, CVE-2013-5065, and Java vulnerabilities such as CVE-2012-1723. In some cases, Epic Turla served as the first-stage backdoor that profiled victims and selectively upgraded high-value systems to more advanced Turla implants. USB-related propagation and artifact overlap have also been noted in historical comparisons with Agent.BTZ, although the evidence supports technical lineage or reuse more strongly than direct identity.
Turla has targeted both Windows and Linux systems. Windows operations have included fileless or registry-based storage, stealthy persistence, and modular post-compromise tooling. Linux variants, including Penquin and other backdoor modules, have provided covert network communications and arbitrary shell command execution. Turla has also deployed server-focused implants such as LightNeuron against Exchange infrastructure.
The malware has been tied to numerous high-profile espionage campaigns and victim sets, including compromises of foreign affairs institutions, embassies, government ministries, military-related entities, research organizations, and telecommunications environments. Reporting has also described Turla’s operational flexibility, including rapid tool updates, infrastructure changes when disrupted, and occasional hijacking or reuse of other actors’ access or infrastructure. In 2025, security researchers reported technical evidence of cooperation between Gamaredon and Turla in attacks against Ukrainian targets, with Gamaredon access used to help deploy or restart Turla’s Kazuar implant on selected systems.
Overall, Turla is one of the most prominent Russian cyber-espionage malware ecosystems, notable for its longevity, modularity, stealth, cross-platform reach, and sustained use in strategic intelligence operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Specifically, the company found that, between February and April 2025, tools that Gamaredon had deployed were used to restart and deploy Turla malware on the systems of select victims in Ukraine.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
This became apparent when we investigated an incident which involved a highly sophisticated rootkit. We called it the ‘Sun rootkit’... The ‘Sun rootkit’ and Uroburos are the same.
The tools ... check for the existence of specific files, windows registry entries ... For example, SIG2 includes System\CurrentControlSet\Control\CrashImage and SIG23 includes software\microsoft\NetWin.
"tiny programs for gathering information about the system"
They check for the existence of specific files, windows registry entries, and other signs ... For example, this script looks for the existence of an actual file “winver32.exe” in the very specific $docsandsettings\\$subkey\\Application Data\\winver32.exe path.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Annotations ID Technique Tactic T1027.011 Fileless Storage Defense Evasion Turla
Turla is an advanced persistent threat (APT) group known for using custom backdoors and sophisticated malware for cyber espionage.
Turla is a Russian FSB-linked APT group specializing in high-value cyberespionage operations against diplomatic, government, and private sector targets worldwide. It is known for sophisticated malware such as Kazuar and for hijacking other groups' infrastructure.
A highly sophisticated cyber-espionage malware platform/rootkit. The content says it is complex and versatile, and notes overlap with Agent.BTZ in log-file names and use of the same XOR key for encrypted log files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.