Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-02

Turla

Also known as:SnakeATK13BELUGASTURGEONBlue PythonG0010Group 88Hippo TeamIRON HUNTERITG12KRYPTONMAKERSMARKPacifier APT

As of 2026-07-14, Turla is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning campaign, apt, malware. Also known as Snake, ATK13, BELUGASTURGEON, Blue Python. ATT&CK coverage spans 107 techniques across 14 tactics in 7 of 7 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1082 (System Information Discovery), T1041 (Exfiltration Over C2 Channel).

Tracked threats
75 high · 2 medium
First seen
2026-02-13
Last seen
2026-07-14
ATT&CK techniques
107across 7 of 7 threats
Related CVEs
2Referenced by its activity
Attribution
RussiaNation or origin
Nation: Russia · 7 tracked threat(s) · Categories: CAMPAIGN, APT, MALWARE

Activity timeline

Turla appears in 7 tracked threats between and ; the busiest month was 2026-07 with 3 reports.

ATT&CK techniques observed

107 techniques observed across 7 of 7 tracked threats · Stealth (formerly Defense Evasion) (17), Discovery (12), Command and Control (11), Resource Development (11), Collection (9), Execution (9)
  • T1005 Data from Local System — Collectionobserved in 7 of 7 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 7 of 7 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 5 of 7 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 5 of 7 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 5 of 7 tracked threats
  • T1090 Proxy — Command and Controlobserved in 5 of 7 tracked threats
  • T1102 Web Service — Command and Controlobserved in 5 of 7 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 7 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 5 of 7 tracked threats
  • T1566 Phishing — Initial Accessobserved in 5 of 7 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 4 of 7 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 7 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 4 of 7 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 7 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked Turla activity