G0010: Turla
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.CitationKaspersky TurlaCitationESET Gazer Aug 2017CitationCrowdStrike VENOMOUS BEARCitationESET Turla Mosquito Jan 2018CitationJoint Cybersecurity Advisory AA23-129A Snake Malware May 2023
Security context for executives and security teams
Turla matters because ATT&CK describes it as a long-running cyber espionage group associated with Russia’s FSB, with reported compromises across government, diplomatic, military, education, research, and pharmaceutical sectors in more than 50 countries. For leaders, the practical issue is not a single malware family; it is whether the organization can detect and investigate patient, multi-tool intrusions that may use spearphishing, watering holes, custom backdoors, credential dumping, and legitimate administration utilities.
Executive priority
Prioritize Turla as a readiness benchmark for high-consequence espionage scenarios, especially where sensitive research, government relations, foreign affairs, regulated data, or critical operational knowledge are material to the business. Ask whether incident response, identity controls, endpoint logging, email/web security, and server monitoring can produce audit-quality evidence for long-running compromise—not just block commodity malware. Budget decisions should focus on durable visibility and response capability across endpoints, privileged accounts, email/web entry points, and key servers.
Technical view
ATT&CK does not provide a group-level detection section or tactics for this object, so SOC and IR teams should derive validation from the documented software relationships. Turla is associated with custom backdoors and frameworks including Uroburos, Epic, ComRAT, Gazer, Mosquito, Kazuar, Carbon, PowerStallion, LightNeuron, HyperStack, Crutch, IronNetInjector, and Penquin, as well as dual-use or native tools such as Mimikatz, PsExec, Net, Tasklist, Reg, Systeminfo, Arp, nbtstat, netstat, certutil, and Empire. Detection engineering should validate coverage for suspicious use of administrative utilities, PowerShell and .NET activity, credential dumping indicators, remote execution behavior, registry modification, process and service discovery, network enumeration, backdoor-like command and control, and unusual activity on Microsoft Exchange or Linux systems where related software supports those platforms.
Likely telemetry
- Endpoint process creation with command line arguments for Windows utilities such as PsExec, Net, Reg, Tasklist, Systeminfo, certutil, netstat, nbtstat, and Arp
- PowerShell and script execution logs, including encoded or unusual administrative use where collected
- Authentication and privileged account activity relevant to credential dumping and lateral movement investigations
- Endpoint file, module, service, scheduled task, registry, and persistence-related events
- EDR or host logs from Windows, Linux, and macOS systems where related Turla-associated tools support those platforms
Detection direction
- Do not treat the Turla group page as a ready-made detection rule set; ATT&CK provides no official detection text for this object.
- Build detections around behavior clusters from the related software: credential access, remote execution, discovery commands, registry interaction, PowerShell/.NET execution, backdoor persistence, and unusual server-side mail activity.
- Tune carefully for administrative tools such as PsExec, Net, Reg, certutil, netstat, and Tasklist because legitimate IT operations can look similar; prioritize context such as user, host role, time, parent process, remote source, and command-line intent.
- Validate visibility on non-Windows assets as well as Windows because related tools include Linux, macOS, and cross-platform backdoors, even though the group object itself does not specify platforms.
- Use threat intelligence references to enrich hunts for named tools and aliases, but require local telemetry correlation before escalating to attribution.
Mitigation priorities
- Harden identity first: reduce standing privileges, monitor privileged account use, and ensure rapid credential reset procedures for suspected credential dumping exposure.
- Limit and monitor administrative remote execution and native utilities; establish baselines for expected use of PsExec, Net, Reg, certutil, PowerShell, and similar tools.
- Strengthen email and web controls because ATT&CK notes spearphishing and watering-hole campaigns for Turla.
- Ensure endpoint protection and logging coverage across Windows, Linux, and macOS assets where relevant to the related software set.
- Prioritize monitoring and hardening of high-value servers, including mail infrastructure, research systems, diplomatic or government-facing environments, and repositories of sensitive documents.
Additional notes and limits
This take is based on the official ATT&CK Turla intrusion-set object, its aliases, description, external references, and listed software relationships. The relationship set is valuable for defensive planning because it spans custom espionage malware, backdoors, public frameworks, and legitimate administrative utilities. Use this as a readiness and hunting guide, not as proof that any observed activity is Turla.
The supplied ATT&CK object does not specify group-level platforms, tactics, or detection guidance. Related software includes platform information, but local asset exposure and telemetry quality must determine actual coverage. No active exploitation, current targeting, customer exposure, or guaranteed detection is inferred from the supplied fields.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Turla
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.CitationKaspersky TurlaCitationESET Gazer Aug 2017CitationCrowdStrike VENOMOUS BEARCitationESET Turla Mosquito Jan 2018CitationJoint Cybersecurity Advisory AA23-129A Snake Malware May 2023
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
