# Turla

> As of 2026-07-14, Turla is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning campaign, apt, malware. Also known as Snake, ATK13, BELUGASTURGEON, Blue Python. ATT&CK coverage spans 107 techniques across 14 tactics in 7 of 7 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1082 (System Information Discovery), T1041 (Exfiltration Over C2 Channel).

- **Nation:** Russia
- **Tracked threats:** 7
- **Categories:** CAMPAIGN, APT, MALWARE
- **Also known as:** Snake, ATK13, BELUGASTURGEON, Blue Python, G0010, Group 88, Hippo Team, IRON HUNTER, ITG12, KRYPTON, MAKERSMARK, Pacifier APT
- **As of:** 2026-07-14

## ATT&CK techniques observed

107 techniques observed across 7 of 7 tracked threats. Tactics: Stealth (formerly Defense Evasion) (17), Discovery (12), Command and Control (11), Resource Development (11), Collection (9), Execution (9).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 7 of 7 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 7 of 7 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 5 of 7 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 5 of 7 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 5 of 7 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 5 of 7 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 5 of 7 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 5 of 7 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 5 of 7 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 5 of 7 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 4 of 7 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 7 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 4 of 7 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 4 of 7 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 4 of 7 tracked threats

## Tracked threats

- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-1287) — MEDIUM
- [Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector Server](https://intel.threadlinqs.com/threat/TL-2026-1268) — HIGH
- [Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military](https://intel.threadlinqs.com/threat/TL-2026-1029) — HIGH
- [Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088](https://intel.threadlinqs.com/threat/TL-2026-0966) — HIGH
- [Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with Kernel/Bridge/Worker Architecture](https://intel.threadlinqs.com/threat/TL-2026-0519) — HIGH
- [State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151)](https://intel.threadlinqs.com/threat/TL-2026-0111) — HIGH
- [Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries — FSB-Attributed .NET Modular Implant with HP Printer Impersonation](https://intel.threadlinqs.com/threat/TL-2026-0084) — MEDIUM

## Related CVEs

2 CVEs referenced by tracked Turla activity.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Turla
