🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
TURLA

/actor/turla/  ·  0 intel reports

Year Established
2004
Attribution
Russia (FSB)
Motivation
Espionage, Long-term Intelligence Collection
Modus Operandi (MO)
Satellite-based C2, hijacking other groups' infrastructure, government and embassy targeting
Primary Aliases
Snake, Uroburos, Waterbug, Venomous Bear, WhiteBear, Iron Hunter

Turla is one of the oldest, most technically sophisticated, and most patient threat actors in the history of cyber espionage, attributed with high confidence to Russia's Federal Security Service (FSB). Active for over two decades, Turla has demonstrated a remarkable ability to continuously evolve its tradecraft while maintaining persistent access to high-value targets. The group's primary mandate is intelligence collection against governments, diplomatic missions, military organisations, and research institutions across Europe, Central Asia, and the Middle East.

Turla's technical innovations have repeatedly set new standards for nation-state cyber tradecraft. The group pioneered the use of satellite internet links for command-and-control communications in the early 2010s. This satellite C2 technique remained largely unique to Turla for years before becoming more widely understood.

Perhaps most audaciously, Turla has been documented hijacking the infrastructure of other threat actor groups spying through the infrastructure of another spy group.

Turla's Snake malware platform, a modular peer-to-peer implant framework operational since at least 2004, was the subject of a major disruption operation by US Cyber Command and the FBI in May 2023 (Operation MEDUSA), which remotely neutralised Snake implants across 50+ countries. Despite this disruption, Turla's demonstrated resilience and two-decade operational history suggest the group will continue to pose a significant long-term espionage threat.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles