Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector Server
Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach (TL-2026-1268), also tracked as Snake Malware Campaign, is a high-severity advanced persistent threat campaign, first published 2026-07-13. It is attributed to Turla (Russia) with high confidence, affects Microsoft SharePoint, maps to 19 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1268
- Threat ID
- TL-2026-1268
- Also known as
- Snake Malware Campaign, Operation MEDUSA (disruption)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-07-13
- Last reviewed
- 2026-07-13
- Attribution
- Turla
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomatic, defense, justice, technology, research
- Target regions
- france, Europe, ukraine, North America
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach
Malware and tooling: Carbon - S0335, ComRAT, Crutch - S0538, Gazer, KOPILUWAK - S1075, Kazuar - S0265, LightNeuron - S0395, Mosquito, Snake, Uroburos, Empire - S0363, Mimikatz
Russian FSB-linked APT Turla exploited a Microsoft SharePoint vulnerability in 2019 to compromise a French Ministry of Justice continuing-education server, exposing several thousand user accounts. France's Cyber Crisis Coordination Center (C4) and CERT-FR publicly disclosed the intrusion on 2026-07-13 (CERTFR-2026-CTI-004/005), documenting Turla's use of the Uroburos/Snake and Kazuar implants, public tools (Mimikatz, Metasploit), and a global network of compromised servers, CMS-hosted websites, and satellite links as covert relay infrastructure against French government, diplomatic, defense, justice, and technology-sector targets.
How Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach works
Turla (also tracked as Snake, Uroburos, Venomous Bear, Waterbug, Secret Blizzard, WhiteBear, Krypton, Group 88, IRON HUNTER, BELUGASTURGEON) is a long-running cyber-espionage operation run by Center 16 (Military Unit 61240) of Russia's Federal Security Service (FSB), located near Krasnoye Selo outside Saint Petersburg. Active since at least 2004, Turla has compromised government, diplomatic, defense, research, and technology-sector targets in more than 50 countries.
In 2019, Turla exploited a vulnerability connected to Microsoft SharePoint to gain unauthorized access to a server operated by the French Ministry of Justice that hosted a continuing-education (professional training) platform for justice-sector personnel, ultimately exposing several thousand user accounts. France's Cyber Crisis Coordination Center (C4) and the national CERT (CERT-FR/ANSSI) publicly disclosed this and other Turla activity against French entities on 2026-07-13 in reports CERTFR-2026-CTI-004 (French) and CERTFR-2026-CTI-005 (English), describing sustained targeting of French ministries and diplomatic, defense, justice, and technology organizations, including compromise of Ministry of Defense email accounts and the French Embassy network in Moscow, and a February 2025 intrusion at a defense-industry research institute that resulted in significant data exfiltration.
Turla's toolset combines bespoke, long-maintained implants — the Uroburos/Snake rootkit-backdoor (in continuous development since 2003 and the subject of a May 2023 U.S./international disruption effort, Operation MEDUSA, using the FBI-built PERSEUS tool to remotely neutralize Snake implants) and the Kazuar .NET second-stage backdoor (repeatedly updated, most recently reworked from a monolithic implant into a modular peer-to-peer botnet architecture) — with dual-use and legitimate tools including Mimikatz for credential theft and Metasploit for exploitation and post-exploitation. The group further obscures its operations by hijacking third-party infrastructure: compromised or rented servers, websites running content-management systems, satellite communications links, and other actors' infected-machine networks (including infrastructure previously associated with Iranian threat groups) are used as intermediary relays, decoupling victim traffic from FSB-controlled endpoints. Since Russia's February 2022 invasion of Ukraine, Turla has intensified intelligence-collection operations against Ukraine, NATO members, and EU states, of which the newly disclosed French justice-sector compromise is part.
MITRE ATT&CK techniques used in TL-2026-1268
Credential Access
Collection
T1005 Data from Local System; T1025 Data from Removable Media
Discovery
T1018 Remote System Discovery; T1057 Process Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing
Lateral Movement
T1210 Exploitation of Remote Services
Persistence
T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution
Exfiltration
Affected products and versions in Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach
- Microsoft — SharePoint
Vulnerable versions: On-premises SharePoint Server deployments exposed to the internet, exact version/CVE undisclosed in source reporting
Fixed in: Current vendor-supported cumulative security updates - French Ministry of Justice — Continuing-education/professional-training server
Vulnerable versions: 2019-era deployment
Fixed in: Not specified in public disclosure
Remediation for Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach
Patches
- Apply current Microsoft SharePoint security updates; validate against all historically exploited SharePoint RCE issues (e.g., CVE-2019-0604-class deserialization/markup-validation flaws) even where the specific CVE for this intrusion was not publicly disclosed
Immediate actions
- Patch all internet-facing Microsoft SharePoint deployments to the latest vendor-supported cumulative update and confirm no exploitation artifacts (webshells, unusual App Pool child processes) are present
- Force credential reset and enable MFA for all accounts on the affected continuing-education/training platform and any systems it shares an authentication domain with
- Hunt for Mimikatz and Metasploit artifacts (LSASS access events, unsigned meterpreter-style process trees) on justice-, defense-, and diplomatic-sector servers
- Audit outbound traffic to satellite-linked IP ranges, CMS-hosted third-party domains, and other unusual relay-pattern destinations
Workarounds
- Where patching is delayed, restrict SharePoint administrative and app-package upload functionality to trusted internal networks only
- Disable or tightly restrict SharePoint features that process untrusted application packages/markup until patched
Longer-term hardening
- Deploy EDR with behavioral detection tuned to Turla TTPs (WMI event-subscription persistence, PowerShell/JavaScript living-off-the-land execution, LSASS credential dumping)
- Segment training/continuing-education platforms from core justice-sector production networks and directory services
- Establish continuous threat-intel ingestion of CERT-FR and CISA Turla/Snake advisories for IOC updates
- Adopt network-level detection for peer-to-peer/relay C2 patterns consistent with Snake's covert P2P infrastructure model
Weaknesses (CWE) in Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach
CWE-502, CWE-20
Timeline of Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach
- Turla's Uroburos/Snake implant development completes and FSB Center 16 begins conducting cyber operations with it; the group's activity against government, diplomatic, defense, and research targets begins tracking from this period.
- Turla exploits a vulnerability connected to Microsoft SharePoint to breach a French Ministry of Justice continuing-education server, ultimately exposing several thousand user accounts.
- Following Russia's invasion of Ukraine, Turla intensifies intelligence-collection operations against Ukraine, NATO members, and EU states, including France.
- The U.S. Department of Justice and international partners announce Operation MEDUSA, using the FBI-developed PERSEUS tool to remotely disable the Snake malware's peer-to-peer infrastructure across 50+ countries; CISA publishes advisory AA23-129A.
- Turla is observed updating the Kazuar backdoor with advanced anti-analysis and anti-detection capabilities.
- Turla compromises a French defense-industry research institute, resulting in significant data exfiltration.
- Reporting describes Turla reworking Kazuar from a monolithic backdoor into a modular peer-to-peer botnet architecture for persistent access.
- France's Cyber Crisis Coordination Center (C4) and CERT-FR publicly disclose the 2019 justice-sector compromise and broader Turla targeting of French entities via reports CERTFR-2026-CTI-004/005.
Sources cited for Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach
- Turla Hackers Exploit SharePoint Flaw
- CERTFR-2026-CTI-004: Ciblage et compromission d'entités françaises au moyen du mode opératoire d'attaque Turla
- CERTFR-2026-CTI-005: Targeting and Compromise of French Entities Using the Turla Intrusion Set
- Turla, IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, Group G0010
- Hunting Russian Intelligence "Snake" Malware (AA23-129A)
- Threat Group Assessment: Turla (aka Pensive Ursa)
- Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
- Turla Updates Kazuar Backdoor with Advanced Anti-Analysis to Evade Detection
- Russie et cybercriminalité : ce qu'il faut savoir sur Turla, l'outil attribué au FSB russe
- Turla (Threat Actor) — Malpedia
Threats related to Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against Ukraine
- Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
Detection coverage for TL-2026-1268
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1268 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.