Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector Server

Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach (TL-2026-1268), also tracked as Snake Malware Campaign, is a high-severity advanced persistent threat campaign, first published 2026-07-13. It is attributed to Turla (Russia) with high confidence, affects Microsoft SharePoint, maps to 19 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1268

Threat ID
TL-2026-1268
Also known as
Snake Malware Campaign, Operation MEDUSA (disruption)
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-07-13
Last reviewed
2026-07-13
Attribution
Turla
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, diplomatic, defense, justice, technology, research
Target regions
france, Europe, ukraine, North America
Detection rules
9
Indicators of compromise
20

Malware and tooling in Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach

Malware and tooling: Carbon - S0335, ComRAT, Crutch - S0538, Gazer, KOPILUWAK - S1075, Kazuar - S0265, LightNeuron - S0395, Mosquito, Snake, Uroburos, Empire - S0363, Mimikatz

Russian FSB-linked APT Turla exploited a Microsoft SharePoint vulnerability in 2019 to compromise a French Ministry of Justice continuing-education server, exposing several thousand user accounts. France's Cyber Crisis Coordination Center (C4) and CERT-FR publicly disclosed the intrusion on 2026-07-13 (CERTFR-2026-CTI-004/005), documenting Turla's use of the Uroburos/Snake and Kazuar implants, public tools (Mimikatz, Metasploit), and a global network of compromised servers, CMS-hosted websites, and satellite links as covert relay infrastructure against French government, diplomatic, defense, justice, and technology-sector targets.

How Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach works

Turla (also tracked as Snake, Uroburos, Venomous Bear, Waterbug, Secret Blizzard, WhiteBear, Krypton, Group 88, IRON HUNTER, BELUGASTURGEON) is a long-running cyber-espionage operation run by Center 16 (Military Unit 61240) of Russia's Federal Security Service (FSB), located near Krasnoye Selo outside Saint Petersburg. Active since at least 2004, Turla has compromised government, diplomatic, defense, research, and technology-sector targets in more than 50 countries.

In 2019, Turla exploited a vulnerability connected to Microsoft SharePoint to gain unauthorized access to a server operated by the French Ministry of Justice that hosted a continuing-education (professional training) platform for justice-sector personnel, ultimately exposing several thousand user accounts. France's Cyber Crisis Coordination Center (C4) and the national CERT (CERT-FR/ANSSI) publicly disclosed this and other Turla activity against French entities on 2026-07-13 in reports CERTFR-2026-CTI-004 (French) and CERTFR-2026-CTI-005 (English), describing sustained targeting of French ministries and diplomatic, defense, justice, and technology organizations, including compromise of Ministry of Defense email accounts and the French Embassy network in Moscow, and a February 2025 intrusion at a defense-industry research institute that resulted in significant data exfiltration.

Turla's toolset combines bespoke, long-maintained implants — the Uroburos/Snake rootkit-backdoor (in continuous development since 2003 and the subject of a May 2023 U.S./international disruption effort, Operation MEDUSA, using the FBI-built PERSEUS tool to remotely neutralize Snake implants) and the Kazuar .NET second-stage backdoor (repeatedly updated, most recently reworked from a monolithic implant into a modular peer-to-peer botnet architecture) — with dual-use and legitimate tools including Mimikatz for credential theft and Metasploit for exploitation and post-exploitation. The group further obscures its operations by hijacking third-party infrastructure: compromised or rented servers, websites running content-management systems, satellite communications links, and other actors' infected-machine networks (including infrastructure previously associated with Iranian threat groups) are used as intermediary relays, decoupling victim traffic from FSB-controlled endpoints. Since Russia's February 2022 invasion of Ukraine, Turla has intensified intelligence-collection operations against Ukraine, NATO members, and EU states, of which the newly disclosed French justice-sector compromise is part.

MITRE ATT&CK techniques used in TL-2026-1268

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System; T1025 Data from Removable Media

Discovery

T1018 Remote System Discovery; T1057 Process Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing

Lateral Movement

T1210 Exploitation of Remote Services

Persistence

T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach

  • Microsoft — SharePoint
    Vulnerable versions: On-premises SharePoint Server deployments exposed to the internet, exact version/CVE undisclosed in source reporting
    Fixed in: Current vendor-supported cumulative security updates
  • French Ministry of Justice — Continuing-education/professional-training server
    Vulnerable versions: 2019-era deployment
    Fixed in: Not specified in public disclosure

Remediation for Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach

Patches

  • Apply current Microsoft SharePoint security updates; validate against all historically exploited SharePoint RCE issues (e.g., CVE-2019-0604-class deserialization/markup-validation flaws) even where the specific CVE for this intrusion was not publicly disclosed

Immediate actions

  • Patch all internet-facing Microsoft SharePoint deployments to the latest vendor-supported cumulative update and confirm no exploitation artifacts (webshells, unusual App Pool child processes) are present
  • Force credential reset and enable MFA for all accounts on the affected continuing-education/training platform and any systems it shares an authentication domain with
  • Hunt for Mimikatz and Metasploit artifacts (LSASS access events, unsigned meterpreter-style process trees) on justice-, defense-, and diplomatic-sector servers
  • Audit outbound traffic to satellite-linked IP ranges, CMS-hosted third-party domains, and other unusual relay-pattern destinations

Workarounds

  • Where patching is delayed, restrict SharePoint administrative and app-package upload functionality to trusted internal networks only
  • Disable or tightly restrict SharePoint features that process untrusted application packages/markup until patched

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to Turla TTPs (WMI event-subscription persistence, PowerShell/JavaScript living-off-the-land execution, LSASS credential dumping)
  • Segment training/continuing-education platforms from core justice-sector production networks and directory services
  • Establish continuous threat-intel ingestion of CERT-FR and CISA Turla/Snake advisories for IOC updates
  • Adopt network-level detection for peer-to-peer/relay C2 patterns consistent with Snake's covert P2P infrastructure model

Weaknesses (CWE) in Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach

CWE-502, CWE-20

Timeline of Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach

  • Turla's Uroburos/Snake implant development completes and FSB Center 16 begins conducting cyber operations with it; the group's activity against government, diplomatic, defense, and research targets begins tracking from this period.
  • Turla exploits a vulnerability connected to Microsoft SharePoint to breach a French Ministry of Justice continuing-education server, ultimately exposing several thousand user accounts.
  • Following Russia's invasion of Ukraine, Turla intensifies intelligence-collection operations against Ukraine, NATO members, and EU states, including France.
  • The U.S. Department of Justice and international partners announce Operation MEDUSA, using the FBI-developed PERSEUS tool to remotely disable the Snake malware's peer-to-peer infrastructure across 50+ countries; CISA publishes advisory AA23-129A.
  • Turla is observed updating the Kazuar backdoor with advanced anti-analysis and anti-detection capabilities.
  • Turla compromises a French defense-industry research institute, resulting in significant data exfiltration.
  • Reporting describes Turla reworking Kazuar from a monolithic backdoor into a modular peer-to-peer botnet architecture for persistent access.
  • France's Cyber Crisis Coordination Center (C4) and CERT-FR publicly disclose the 2019 justice-sector compromise and broader Turla targeting of French entities via reports CERTFR-2026-CTI-004/005.

Sources cited for Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach

Threats related to Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach

Detection coverage for TL-2026-1268

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1268 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats