Turla

☆ pin
MITRE G0010Also known as Secret Blizzard, ATG26, Blue Python, Iron Hunter, Pensive Ursa, Snake, SUMMIT, Uroburos, Venomous Bear, Waterbug, WRAITH
Reports
15
First seen
Oct 1, 2025
Last seen
Aug 3, 2026
Motivation
Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×5
×5
Ukraine×5

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566 Phishing ×12T1041 Exfiltration Over C2 Channel ×7T1547 Boot or Logon Autostart Execution ×6T1005 Data from Local System ×6T1059.001 PowerShell ×5T1190 Exploit Public-Facing Application ×5T1598 Phishing for Information ×4T1071 Application Layer Protocol ×3T1105 Ingress Tool Transfer ×3T1566.002 Phishing: Spearphishing Attachment ×3T1486 Data Encrypted for Impact ×3T1059 Command and Scripting Interpreter ×3

Indicators

cve ×47domain ×27hash_sha256 ×4email ×1filename ×1hash_md5 ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

Cyber Brief July 2026 – EU Threat Intelligence Summary

CERT-EU Threat Intel
High

Europe sanctions Russia's Turla over years-long cyberespionage and destructive attacks

CyberScoop
High

EU and UK sanction Russian GRU military hackers over coordinated cyberattacks

Bleeping Computer
High

Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More

The Hacker News
High

Threat Intelligence Report – 29 June: Breaches, AI Threats, and Active Exploits

Check Point Research
High

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

The Hacker News
High

Turla group adds more malware to Russia's espionage efforts against Ukraine

The Record (Recorded Future News)
High

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

The Hacker News
High

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

ESET WeLiveSecurity
High

Threats to the 2026 FIFA World Cup: Physical Security, Cyber, and Influence Operations Risk Assessment

Recorded Future Insikt
Critical

Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine

SentinelOne Labs
High

Turla Transforms Kazuar Backdoor Into Modular P2P Botnet

The Hacker News
Critical

Kazuar: Anatomy of a nation-state botnet

Microsoft Threat Intelligence
High

ESET APT Activity Report Q2 2025–Q3 2025

ESET WeLiveSecurity
High

CERT-EU Cyber Brief September 2025 – Multi-Sector Threats Across Europe

CERT-EU Threat Intel

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.