Turla is a long-running Russian state-sponsored cyber espionage threat actor widely attributed to the 16th Centre of the Federal Security Service (FSB). Active since at least the early 2000s, and often described as operating since the late 1990s, Turla is known for persistent, covert intelligence collection against government, diplomatic, defense, justice, technology, and critical infrastructure targets. Victimology has consistently included ministries, foreign affairs organizations, military and defense bodies, embassies, research institutions, and other strategic entities across Europe, Ukraine, NATO member states, and other regions of geopolitical interest to Russia. Turla is tracked under numerous aliases, including Secret Blizzard, Waterbug, Venomous Bear, Pensive Ursa, WhiteBear, Uroburos, Snake, Krypton, Iron Hunter, Blue Python, Beluga Sturgeon, Group 88, Wraith, and UAC-0003. Snake and Uroburos are also associated with Turla’s best-known malware and intrusion set branding. Public reporting and government attributions have linked Turla directly to FSB Centre 16, and European authorities have publicly stated that this unit controls or directs the group. The group specializes in long-term access, stealthy persistence, communications exploitation, and strategic surveillance. Its tradecraft includes spearphishing, watering-hole operations, exploitation of internet-facing systems, abuse of peripheral or less-defended platforms to gain footholds, credential theft, use of compromised infrastructure as relays, and compromise of routers and other network devices for covert persistence and traffic handling. Turla has also been associated with hijacking trusted communications paths and blending operations into legitimate network traffic to reduce detection. Turla has operated across Windows, Linux, and macOS environments and has targeted servers, email systems, browsers, business applications, and network infrastructure. Malware and tooling associated with the group include Snake/Uroburos, Kazuar, ComRAT, and STOCKSTAY, alongside use of publicly available post-exploitation tools such as Mimikatz and Metasploit. The group has demonstrated persistence techniques including COM-related hijacking methods such as TreatAs and TypeLib abuse, and has been associated with process injection and privilege-escalation tradecraft. Recent reporting has highlighted Turla activity against Ukrainian and European diplomatic organizations, as well as long-running compromises affecting French governmental and strategic entities. French authorities have linked Turla intrusions to espionage-focused operations against ministries, diplomatic organizations, defense bodies, justice-sector entities, and technology companies, including compromises involving vulnerable public-facing collaboration infrastructure. European and UK government statements in 2026 further tied Turla and FSB Centre 16 to broader campaigns targeting government networks and critical infrastructure across multiple European states. Turla is best characterized as a mature, highly capable FSB espionage actor focused on durable access and intelligence collection in support of Russian state objectives. Its operations emphasize patience, operational security, layered infrastructure, and adaptable malware and persistence mechanisms rather than overt disruption, although the broader FSB Centre 16 ecosystem has also been publicly accused by European governments of involvement in sabotage-oriented activity against critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
54 malware families attributed to this actor across reporting.
49 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
That campaign used malicious RAR archives exploiting a WinRAR path traversal flaw tracked as CVE-2025-8088.
The Java files exploit a popular vulnerability, CVE-2012-1723, in various configurations.
CVE-2013-3346 – Arbitrary code-execution vulnerability in Adobe Reader
The attacks are known to have used at least two zero-day exploits: CVE-2013-5065 – Privilege escalation vulnerability in Windows XP and Windows 2003
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
3 more CVEs tied to this actor tracked in Mallory.
283 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for attacks on diplomatic entities and foreign ministries via peripheral systems.
Mentioned as an example threat actor associated with COM hijacking/persistence techniques in a pedagogical offensive research repository about Windows COM attack surface.
FSB-attributed Russian APT specializing in long-term operations and covert persistence.
Conducts strategic cyberespionage, covert access, communications exploitation, and long-term surveillance against government, diplomatic, military, research, and media targets to achieve information superiority.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.