Turla
MISPNation-state
RU
Unknown
[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. [Turla](https://attack.mitre.org/groups/G0010) is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as [Uroburos](https://attack.mitre.org/software/S0022).(Citation: Kaspersky Turla)(Citation: ESET Gazer Aug 2017)(Citation: CrowdStrike VENOMOUS BEAR)(Citation: ESET Turla Mosquito Jan 2018)(Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023)
Techniques Used (68)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1005 | Data from Local System | - |
| T1007 | System Service Discovery | - |
| T1012 | Query Registry | - |
| T1016 | System Network Configuration Discovery | - |
| T1016.001 | Internet Connection Discovery | - |
| T1018 | Remote System Discovery | - |
| T1021.002 | SMB/Windows Admin Shares | - |
| T1025 | Data from Removable Media | - |
| T1027.005 | Indicator Removal from Tools | - |
| T1027.010 | Command Obfuscation | - |
| T1027.011 | Fileless Storage | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1049 | System Network Connections Discovery | - |
| T1055 | Process Injection | - |
| T1055.001 | Dynamic-link Library Injection | - |
Aliases (3511)
Related Malware (30)
Metadata
| ID: | 56 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |