> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
TURLA
/actor/turla/ · 0 intel reports
Turla is one of the oldest, most technically sophisticated, and most patient threat actors in the history of cyber espionage, attributed with high confidence to Russia's Federal Security Service (FSB). Active for over two decades, Turla has demonstrated a remarkable ability to continuously evolve its tradecraft while maintaining persistent access to high-value targets. The group's primary mandate is intelligence collection against governments, diplomatic missions, military organisations, and research institutions across Europe, Central Asia, and the Middle East.
Turla's technical innovations have repeatedly set new standards for nation-state cyber tradecraft. The group pioneered the use of satellite internet links for command-and-control communications in the early 2010s. This satellite C2 technique remained largely unique to Turla for years before becoming more widely understood.
Perhaps most audaciously, Turla has been documented hijacking the infrastructure of other threat actor groups spying through the infrastructure of another spy group.
Turla's Snake malware platform, a modular peer-to-peer implant framework operational since at least 2004, was the subject of a major disruption operation by US Cyber Command and the FBI in May 2023 (Operation MEDUSA), which remotely neutralised Snake implants across 50+ countries. Despite this disruption, Turla's demonstrated resilience and two-decade operational history suggest the group will continue to pose a significant long-term espionage threat.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.