{"id":440,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2004<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Russia (FSB)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Long-term Intelligence Collection<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Satellite-based C2, hijacking other groups' infrastructure, government and embassy targeting<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Snake, Uroburos, Waterbug, Venomous Bear, WhiteBear, Iron Hunter<\/div>\n  <\/div>\n<\/div>\n<p>Turla is one of the oldest, most technically sophisticated, and most patient threat actors in the history of cyber espionage, attributed with high confidence to Russia's Federal Security Service (FSB). Active for over two decades, Turla has demonstrated a remarkable ability to continuously evolve its tradecraft while maintaining persistent access to high-value targets \u2014 in some cases maintaining undiscovered footholds in government networks for years or even decades. The group's primary mandate is intelligence collection against governments, diplomatic missions, military organisations, and research institutions across Europe, Central Asia, and the Middle East.<\/p>\n<p>Turla's technical innovations have repeatedly set new standards for nation-state cyber tradecraft. The group pioneered the use of satellite internet links for command-and-control communications in the early 2010s \u2014 hijacking legitimate satellite broadband connections of unsuspecting subscribers to receive communications from implants in target networks, making the C2 infrastructure virtually impossible to take down or attribute. This satellite C2 technique remained largely unique to Turla for years before becoming more widely understood.<\/p>\n<p>Perhaps most audaciously, Turla has been documented hijacking the infrastructure of other threat actor groups \u2014 specifically compromising the C2 servers of Iranian APT group OilRig (APT34) and using their already-deployed implants in victim networks as a secondary access channel. This \"fourth-party collection\" technique \u2014 spying through the infrastructure of another spy group \u2014 demonstrates extraordinary operational creativity and a willingness to exploit rival intelligence services' work.<\/p>\n<p>Turla's Snake malware platform, a modular peer-to-peer implant framework operational since at least 2004, was the subject of a major disruption operation by US Cyber Command and the FBI in May 2023 (Operation MEDUSA), which remotely neutralised Snake implants across 50+ countries. Despite this disruption, Turla's demonstrated resilience and two-decade operational history suggest the group will continue to pose a significant long-term espionage threat.<\/p>","link":"https:\/\/cyberasia.io\/actor\/turla\/","name":"Turla","slug":"turla","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}