LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0010: Turla

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]

EnterpriseG0010GroupObject v5.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0010: Turla describes [Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. [Turla](https://attack.mitre.org/groups/G0010) is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as [Uroburos...

Executive priority

G0010: Turla is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0010: Turla by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0010: Turla appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Turla

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

56 rows
DomainIDNameRelationship / procedure
EnterpriseT1584.006Web ServicesSub-technique

Turla has frequently used compromised WordPress sites for C2 infrastructure.CitationRecorded Future Turla Infra 2020

EnterpriseT1112Modify Registry

Turla has modified Registry values to store payloads.[6]CitationSymantec Waterbug Jun 2019

EnterpriseT1069.001Local GroupsSub-technique

Turla has used net localgroup and net localgroup Administrators to enumerate group information, including members of the local administrators group.CitationESET ComRAT May 2020

EnterpriseT1140Deobfuscate/Decode Files or Information

Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads.[6]

EnterpriseT1588.002ToolSub-technique

Turla has obtained and customized publicly-available tools like Mimikatz.CitationSymantec Waterbug Jun 2019

EnterpriseT1059.007JavaScriptSub-technique

Turla has used various JavaScript-based backdoors.[4]

EnterpriseT1134.002Create Process with TokenSub-technique

Turla RPC backdoors can impersonate or steal process tokens before executing commands.[6]

EnterpriseT1059.005Visual BasicSub-technique

Turla has used VBS scripts throughout its operations.CitationSymantec Waterbug Jun 2019

EnterpriseT1546.013PowerShell ProfileSub-technique

Turla has used PowerShell profiles to maintain persistence on an infected machine.[6]

EnterpriseT1583.006Web ServicesSub-technique

Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration.CitationESET Crutch December 2020

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges.CitationESET Turla Mosquito May 2018CitationGithub Rapid7 Meterpreter Elevate

EnterpriseT1105Ingress Tool Transfer

Turla has used shellcode to download Meterpreter after compromising a victim.CitationESET Turla Mosquito May 2018

EnterpriseT1555.004Windows Credential ManagerSub-technique

Turla has gathered credentials from the Windows Credential Manager tool.CitationSymantec Waterbug Jun 2019

EnterpriseT1090Proxy

Turla RPC backdoors have included local UPnP RPC proxies.[6]

EnterpriseT1068Exploitation for Privilege Escalation

Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges.CitationUnit42 AcidBox June 2020

EnterpriseT1615Group Policy Discovery

Turla surveys a system upon check-in to discover Group Policy details using the gpresult command.CitationESET ComRAT May 2020

EnterpriseT1049System Network Connections Discovery

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands.[1]CitationESET ComRAT May 2020 Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.[6]

EnterpriseT1106Native API

Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes.[6]

EnterpriseT1071.003Mail ProtocolsSub-technique

Turla has used multiple backdoors which communicate with a C2 server via email attachments.CitationCrowdstrike GTR2020 Mar 2020

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Turla used net use commands to connect to lateral systems within a network.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

A Turla Javascript backdoor added a local_update_check value under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence. Additionally, a Turla custom executable containing Metasploit shellcode is saved to the Startup folder to gain persistence.[4]CitationESET Turla Mosquito May 2018CitationESET Turla Lunar toolset May 2024

EnterpriseT1005Data from Local System

Turla RPC backdoors can upload files from victim machines.[6]

EnterpriseT1012Query Registry

Turla surveys a system upon check-in to discover information in the Windows Registry with the reg query command.[1] Turla has also retrieved PowerShell payloads hidden in Registry keys as well as checking keys associated with null session named pipes .[6]

EnterpriseT1007System Service Discovery

Turla surveys a system upon check-in to discover running services and associated processes using the tasklist /svc command.[1]

EnterpriseT1110Brute Force

Turla may attempt to connect to systems within a victim's network using net use commands and a predefined list or collection of passwords.[1]

EnterpriseT1570Lateral Tool Transfer

Turla RPC backdoors can be used to transfer files to/from victim machines on the local network.[6]CitationSymantec Waterbug Jun 2019

EnterpriseT1189Drive-by Compromise

Turla has infected victims using watering holes.CitationESET ComRAT May 2020[8]

EnterpriseT1584.004ServerSub-technique

Turla has used compromised servers as infrastructure.CitationRecorded Future Turla Infra 2020[9][10]

EnterpriseT1087.002Domain AccountSub-technique

Turla has used net user /domain to enumerate domain accounts.CitationESET ComRAT May 2020

EnterpriseT1685Disable or Modify Tools

Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products.[6]

EnterpriseT1564.012File/Path ExclusionsSub-technique

Turla has placed LunarWeb install files into directories that are excluded from scanning.CitationESET Turla Lunar toolset May 2024

EnterpriseT1120Peripheral Device Discovery

Turla has used fsutil fsinfo drives to list connected drives.CitationESET ComRAT May 2020

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Turla has used WebDAV to upload stolen USB files to a cloud drive.CitationSymantec Waterbug Jun 2019 Turla has also exfiltrated stolen files to OneDrive and 4shared.CitationESET ComRAT May 2020

EnterpriseT1102.002Bidirectional CommunicationSub-technique

A Turla JavaScript backdoor has used Google Apps Script as its C2 server.[4]CitationESET Turla Mosquito May 2018

EnterpriseT1071.001Web ProtocolsSub-technique

Turla has used HTTP and HTTPS for C2 communications.[4]CitationESET Turla Mosquito May 2018

EnterpriseT1124System Time Discovery

Turla surveys a system upon check-in to discover the system time by using the net time command.[1]

EnterpriseT1087.001Local AccountSub-technique

Turla has used net user to enumerate local accounts on the system.CitationESET ComRAT May 2020CitationESET Crutch December 2020

EnterpriseT1204.001Malicious LinkSub-technique

Turla has used spearphishing via a link to get users to download and run their malware.[4]

EnterpriseT1090.001Internal ProxySub-technique

Turla has compromised internal network systems to act as a proxy to forward traffic to C2.[10]

EnterpriseT1546.003Windows Management Instrumentation Event SubscriptionSub-technique

Turla has used WMI event filters and consumers to establish persistence.[6]

EnterpriseT1560.001Archive via UtilitySub-technique

Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration.CitationSymantec Waterbug Jun 2019

EnterpriseT1059.003Windows Command ShellSub-technique

Turla RPC backdoors have used cmd.exe to execute commands.[6]CitationSymantec Waterbug Jun 2019

EnterpriseT1057Process Discovery

Turla surveys a system upon check-in to discover running processes using the tasklist /v command.[1] Turla RPC backdoors have also enumerated processes associated with specific open ports or named pipes.[6]

EnterpriseT1016System Network Configuration Discovery

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan.[1]CitationSymantec Waterbug Jun 2019CitationESET ComRAT May 2020 Turla RPC backdoors have also retrieved registered RPC interface information from process memory.[6]

EnterpriseT1587.001MalwareSub-technique

Turla has developed its own unique malware for use in operations.CitationRecorded Future Turla Infra 2020

EnterpriseT1025Data from Removable Media

Turla RPC backdoors can collect files from USB thumb drives.[6]CitationSymantec Waterbug Jun 2019

EnterpriseT1518.001Security Software DiscoverySub-technique

Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected.CitationESET ComRAT May 2020

EnterpriseT1059.001PowerShellSub-technique

Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject.CitationESET Turla Mosquito May 2018[6]CitationSymantec Waterbug Jun 2019 Turla has also used PowerShell scripts to load and execute malware in memory.

EnterpriseT1027.010Command ObfuscationSub-technique

Turla has used encryption (including salted 3DES via PowerSploit's Out-EncryptedScript.ps1), random variable names, and base64 encoding to obfuscate PowerShell commands and payloads.[6]

EnterpriseT1059.006PythonSub-technique

Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads.CitationUnit 42 IronNetInjector February 2021

EnterpriseT1213.006DatabasesSub-technique

Turla has used a custom .NET tool to collect documents from an organization's internal central database.CitationESET ComRAT May 2020

EnterpriseT1018Remote System Discovery

Turla surveys a system upon check-in to discover remote systems on a local network using the net view and net view /DOMAIN commands. Turla has also used net group "Domain Computers" /domain, net group "Domain Controllers" /domain, and net group "Exchange Servers" /domain to enumerate domain computers, including the organization's DC and Exchange Server.[1]CitationESET ComRAT May 2020

EnterpriseT1588.001MalwareSub-technique

Turla has used malware obtained after compromising other threat actors, such as OilRig.CitationNSA NCSC Turla OilRigCitationRecorded Future Turla Infra 2020

EnterpriseT1069.002Domain GroupsSub-technique

Turla has used net group "Domain Admins" /domain to identify domain administrators.CitationESET ComRAT May 2020

EnterpriseT1027.011Fileless StorageSub-technique

Turla has used the Registry to store encrypted and encoded payloads.[6]CitationSymantec Waterbug Jun 2019

EnterpriseT1547.004Winlogon Helper DLLSub-technique

Turla established persistence by adding a Shell value under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.[4]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S0126: ComRAT

ComRAT is a second stage implant suspected of being a descendant of Agent.btz and used by Turla. The first version of ComRAT was identified in 2007, but the tool has undergone substantial development for many years since.[1][2][3]

Windows
ToolEnterprise

S0104: netstat

netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics. [1]

ToolEnterprise

S0160: certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

Windows
ToolEnterprise

S0363: Empire

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]

LinuxmacOSWindows
MalwareEnterprise

S0256: Mosquito

Mosquito is a Win32 backdoor that has been used by Turla. Mosquito is made up of three parts: the installer, the launcher, and the backdoor. The main backdoor is called CommanderDLL and is launched by the loader program. [1]

Windows
ToolEnterprise

S0099: Arp

Arp displays and modifies information about a system's Address Resolution Protocol (ARP) cache. [1]

LinuxWindowsmacOS
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
5.1
Created
Modified
Raw hash
4e440e5e5bb049d7...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.25.1Current bundle4e440e5e5bb0…
19.15.1Older bundleb67d6f0bd028…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  2. [2]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  3. [3]
    CrowdStrike VENOMOUS BEAR

    Meyers, A. (2018, March 12). Meet CrowdStrike’s Adversary of the Month for March: VENOMOUS BEAR. Retrieved May 16, 2018.

    Open source URL
  4. [4]
    ESET Turla Mosquito Jan 2018

    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

    Open source URL
  5. [5]
    Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023

    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.

    Open source URL
  6. [6]
    ESET Turla PowerShell May 2019

    Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.

    Open source URL
  7. [7]
    Symantec Waterbug

    Symantec. (2015, January 26). The Waterbug attack group. Retrieved April 10, 2015.

    Open source URL
  8. [8]
    Secureworks IRON HUNTER Profile

    Secureworks CTU. (n.d.). IRON HUNTER. Retrieved February 22, 2022.

  9. [9]
    Accenture HyperStack October 2020

    Accenture. (2020, October). Turla uses HyperStack, Carbon, and Kazuar to compromise government entity. Retrieved December 2, 2020.

    Open source URL
  10. [10]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  11. [11]
    BELUGASTURGEON

    (Citation: Accenture HyperStack October 2020)

  12. [12]
    Group 88

    (Citation: Leonardo Turla Penquin May 2020)

  13. [13]
    IRON HUNTER

    (Citation: Secureworks IRON HUNTER Profile)

  14. [14]
    Krypton

    (Citation: CrowdStrike VENOMOUS BEAR)

  15. [15]
    Leonardo Turla Penquin May 2020

    Leonardo. (2020, May 29). MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64”. Retrieved March 11, 2021.

    Open source URL
  16. [16]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  17. [17]
    Secret Blizzard

    (Citation: Microsoft Threat Actor Naming July 2023)

  18. [18]
    Securelist WhiteBear Aug 2017

    Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.

    Open source URL
  19. [19]
    Snake

    (Citation: CrowdStrike VENOMOUS BEAR)(Citation: ESET Turla PowerShell May 2019)(Citation: Talos TinyTurla September 2021)

  20. [20]
    Turla

    (Citation: Kaspersky Turla)

  21. [21]
    Venomous Bear

    (Citation: CrowdStrike VENOMOUS BEAR)(Citation: Talos TinyTurla September 2021)

  22. [22]
    Waterbug

    Based similarity in TTPs and malware used, Turla and Waterbug appear to be the same group.(Citation: Symantec Waterbug)

  23. [23]
    WhiteBear

    WhiteBear is a designation used by Securelist to describe a cluster of activity that has overlaps with activity described by others as Turla, but appears to have a separate focus.(Citation: Securelist WhiteBear Aug 2017)(Citation: Talos TinyTurla September 2021)

  24. [24]
    mitre-attackG0010
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.