Turla
MITRE G0010Also known as Secret Blizzard, ATG26, Blue Python, Iron Hunter, Pensive Ursa, Snake, SUMMIT, Uroburos, Venomous Bear, Waterbug, WRAITH
Reports
15
First seen
Oct 1, 2025
Last seen
Aug 3, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×5×5
Ukraine×5
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×12T1041 Exfiltration Over C2 Channel ×7T1547 Boot or Logon Autostart Execution ×6T1005 Data from Local System ×6T1059.001 PowerShell ×5T1190 Exploit Public-Facing Application ×5T1598 Phishing for Information ×4T1071 Application Layer Protocol ×3T1105 Ingress Tool Transfer ×3T1566.002 Phishing: Spearphishing Attachment ×3T1486 Data Encrypted for Impact ×3T1059 Command and Scripting Interpreter ×3
Indicators
cve ×47domain ×27hash_sha256 ×4email ×1filename ×1hash_md5 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-8088 (exploited)CVE-2024-42009 (exploited)CVE-2025-20333 (exploited)CVE-2025-20352 (exploited)CVE-2025-20362 (exploited)CVE-2025-43300 (exploited)CVE-2025-55177 (exploited)CVE-2025-55241CVE-2025-5777 (exploited)CVE-2026-12569 (exploited)CVE-2026-12957CVE-2026-15409 (exploited)CVE-2026-15410 (exploited)CVE-2026-20245 (exploited)CVE-2026-25089 (exploited)CVE-2026-33017 (exploited)CVE-2026-34908 (exploited)CVE-2026-34909 (exploited)CVE-2026-34910 (exploited)CVE-2026-39808 (exploited)
Recent reports
High