Activity timeline
Turla appears in 7 tracked threats between and ; the busiest month was 2026-07 with 3 reports.
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 7 of 7 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 7 of 7 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 5 of 7 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 5 of 7 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 5 of 7 tracked threats
- T1090 Proxy — Command and Controlobserved in 5 of 7 tracked threats
- T1102 Web Service — Command and Controlobserved in 5 of 7 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 7 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistenceobserved in 5 of 7 tracked threats
- T1566 Phishing — Initial Accessobserved in 5 of 7 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 4 of 7 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
- T1057 Process Discovery — Discoveryobserved in 4 of 7 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 7 tracked threats
Tracked threats
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector ServerHIGH
- Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian MilitaryHIGH
- Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088HIGH
- Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with Kernel/Bridge/Worker ArchitectureHIGH
- State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151)HIGH
- Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries — FSB-Attributed .NET Modular Implant with HP Printer ImpersonationMEDIUM