Turla
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 04/05/2026 16:33
- Updated at
- 04/05/2026 16:33
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 5 reports, 132 attack patterns (mitre), 39 malware, 8 sectors, 7 countries, 100 indicators, 2 vulnerabilities (cve), 12 tool
Aliases
IRON HUNTER Group 88 Waterbug WhiteBear Snake Krypton Venomous Bear BELUGASTURGEON Secret Blizzard
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
- ESET Turla PowerShell May 2019
- Securelist WhiteBear Aug 2017
- CrowdStrike VENOMOUS BEAR
- Symantec Waterbug
- ESET Gazer Aug 2017
- Microsoft Threat Actor Naming July 2023
- Kaspersky Turla
- Leonardo Turla Penquin May 2020
- mitre-attack (G0010)
- Accenture HyperStack October 2020
- Accenture HyperStack October 2020
- ESET Turla Mosquito Jan 2018
- Talos TinyTurla September 2021
- Secureworks IRON HUNTER Profile
- Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (5)
-
AlienVault Confidence 100 24 MITREs 2 Malwares 4 IOCs 4 Observables 1 APTPublished 14/05/2026 22:10 · Modified 15/05/2026 19:14 · threat-report
-
6 MITREs 1 Malware 15 Observables 1 APTPublished 15/01/2026 15:21 · Modified 15/01/2026 15:40
-
19 MITREs 5 Observables 1 APTPublished 27/09/2024 17:23 · Modified 27/09/2024 17:47
-
7 MITREs 2 Malwares 10 Observables 1 APTPublished 08/07/2024 10:45 · Modified 08/07/2024 10:55
-
17 MITREs 2 Malwares 12 Observables 1 APTPublished 16/05/2024 09:35 · Modified 16/05/2024 10:01
Attack patterns (MITRE) (132)
-
T1560.001 usesArchive via Utility
-
T1572 usesProtocol Tunneling
-
T1114 usesEmail Collection
-
T1102.002 usesBidirectional Communication
-
T1567 usesExfiltration Over Web Service
-
T1218.011 usesRundll32
-
T1078.003 usesLocal Accounts
-
T1106 usesNative API
-
T1087.002 usesDomain Account
-
T1021.001 usesRemote Desktop Protocol
-
T1571 usesNon-Standard Port
-
T1059.007 usesJavaScript
-
T1583.006 usesWeb Services
-
T1018 usesRemote System Discovery
-
T1562.004 usesDisable or Modify System Firewall
-
Software usesT1592.002
-
T1574.002 uses
-
T1036.004 usesMasquerade Task or Service
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1135 usesNetwork Share Discovery
-
T1078 usesValid Accounts
-
DNS Server usesT1583.002
-
Fileless Storage uses
-
T1584.006 usesWeb Services
-
T1497 usesVirtualization/Sandbox Evasion
-
T1070.001 usesClear Windows Event Logs
-
T1071 usesApplication Layer Protocol
-
T1083 usesFile and Directory Discovery
-
T1056 usesInput Capture
-
T1025 usesData from Removable Media
-
T1098 usesAccount Manipulation
-
T1203 usesExploitation for Client Execution
-
Command Obfuscation uses
-
T1505.003 usesWeb Shell
-
T1120 usesPeripheral Device Discovery
-
T1036 usesMasquerading
-
T1562.002 usesDisable Windows Event Logging
-
T1047 usesWindows Management Instrumentation
-
T1048 usesExfiltration Over Alternative Protocol
-
T1078.001 usesDefault Accounts
-
T1132 usesData Encoding
-
T1016 usesSystem Network Configuration Discovery
-
T1114.002 usesRemote Email Collection
-
T1114.001 usesLocal Email Collection
-
T1090 usesProxy
-
T1566.002 usesSpearphishing Link
-
T1204.002 usesMalicious File
-
T1543 usesCreate or Modify System Process
-
T1557 usesAdversary-in-the-Middle
-
T1059.001 usesPowerShell
-
T1497.001 usesSystem Checks
-
T1069 usesPermission Groups Discovery
-
T1105 usesIngress Tool Transfer
-
Add-ins usesT1137.006
-
T1007 usesSystem Service Discovery
-
T1102 usesWeb Service
-
T1027 usesObfuscated Files or Information
-
T1071.001 usesWeb Protocols
-
T1087.001 usesLocal Account
-
T1573 usesEncrypted Channel
-
T1592 usesGather Victim Host Information
-
T1021.002 usesSMB/Windows Admin Shares
-
T1074 usesData Staged
-
T1055.001 usesDynamic-link Library Injection
-
T1555 usesCredentials from Password Stores
-
T1204.001 usesMalicious Link
-
T1046 usesNetwork Service Discovery
-
T1543.002 usesSystemd Service
-
T1010 usesApplication Window Discovery
-
T1027.002 usesSoftware Packing
-
T1059 usesCommand and Scripting Interpreter
-
T1035 uses
-
T1033 usesSystem Owner/User Discovery
-
T1132.002 usesNon-Standard Encoding
-
T1069.002 usesDomain Groups
-
T1041 usesExfiltration Over C2 Channel
-
T1587.001 usesMalware
-
T1090.001 usesInternal Proxy
-
T1574 usesHijack Execution Flow
-
T1005 usesData from Local System
-
Winlogon Helper DLL usesT1547.004
-
T1113 usesScreen Capture
-
T1012 usesQuery Registry
-
T1134.002 usesCreate Process with Token
-
T1598 usesPhishing for Information
-
T1584.004 usesServer
-
T1204 usesUser Execution
-
T1068 usesExploitation for Privilege Escalation
-
T1546.003
-
T1059.006 usesPython
-
T1053 usesScheduled Task/Job
-
T1087 usesAccount Discovery
-
T1190 usesExploit Public-Facing Application
-
T1095 usesNon-Application Layer Protocol
-
T1057 usesProcess Discovery
-
T1546 usesEvent Triggered Execution
-
T1567.002 usesExfiltration to Cloud Storage
-
T1132.001 usesStandard Encoding
-
T1008 usesFallback Channels
-
T1570 usesLateral Tool Transfer
-
T1543.003 usesWindows Service
-
T1573.001 usesSymmetric Cryptography
-
T1590 usesGather Victim Network Information
-
T1553.006 usesCode Signing Policy Modification
-
T1112 usesModify Registry
-
T1124 usesSystem Time Discovery
-
T1590.005 usesIP Addresses
-
T1213 usesData from Information Repositories
-
T1201 usesPassword Policy Discovery
-
PowerShell Profile uses
-
T1553.002 usesCode Signing
-
T1555.004 usesWindows Credential Manager
-
T1547 usesBoot or Logon Autostart Execution
-
T1059.005 usesVisual Basic
-
T1598.003 usesSpearphishing Link
-
T1588.001 usesMalware
-
MSBuild usesT1127.001
-
T1199 usesTrusted Relationship
-
T1020 usesAutomated Exfiltration
-
T1133 usesExternal Remote Services
-
T1573.002 usesAsymmetric Cryptography
-
T1003 usesOS Credential Dumping
-
T1069.001 usesLocal Groups
-
T1110 usesBrute Force
-
T1518 usesSoftware Discovery
-
T1584.003 usesVirtual Private Server
-
T1055 usesProcess Injection
-
T1566 usesPhishing
-
T1059.003 usesWindows Command Shell
-
T1082 usesSystem Information Discovery
Malware (39)
-
QUIETCANARY usesFamily The MITRE Corporation Confidence 100
[QUIETCANARY](https://attack.mitre.org/software/S1076) is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data from victim networks.(Citation: Mandiant Suspected Turla Campaign …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:37 · Modified 27/03/2026 01:05 - TinyTurla-NG
-
MiniPocket usesFamilyPublished 05/12/2024 02:56 · Modified 05/12/2024 02:56
- TurlaPower-NG
-
ActionRat usesFamilyPublished 05/12/2024 02:56 · Modified 05/12/2024 02:56
- HyperStack
-
CrimsonRAT usesFamilyPublished 05/12/2024 02:56 · Modified 05/12/2024 02:56
- Penquin
- Carbon
-
AllaKore usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 21/12/2025 00:13
-
Amadey - S1025 usesFamilyPublished 29/09/2025 08:06 · Modified 29/09/2025 08:06
- TinyTurla
- ApolloShadow
- Epic
-
KazuarV2 usesFamilyPublished 13/12/2024 13:28 · Modified 13/12/2024 13:28
- Capibar
- Kazuar
- KOPILUWAK
-
Uroburos - S0022 usesFamilyPublished 08/07/2024 10:45 · Modified 08/07/2024 10:45
- ComRAT - S0126
-
TinyTurla - S0668 usesFamilyPublished 05/12/2024 02:56 · Modified 05/12/2024 02:56
-
Chisel usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
Kazuar - S0265 usesFamilyPublished 28/05/2026 19:56 · Modified 28/05/2026 19:56
- Crutch
- LunarLoader
- HyperStack - S0537
-
LunarMail usesFamilyPublished 16/05/2024 09:35 · Modified 16/05/2024 09:35
- ComRAT
- Mosquito
- LightNeuron
- Gazer
-
Wainscot usesFamilyPublished 05/12/2024 02:56 · Modified 05/12/2024 02:56
-
TwoDash usesFamilyPublished 05/12/2024 02:56 · Modified 05/12/2024 02:56
-
Pelmeni usesFamilyPublished 14/05/2026 20:10 · Modified 14/05/2026 20:10
-
LunarWeb usesFamilyPublished 16/05/2024 09:35 · Modified 16/05/2024 09:35
- PowerStallion
- Crutch - S0538
-
Statuezy usesFamilyPublished 05/12/2024 02:56 · Modified 05/12/2024 02:56
-
Waiscot usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:49 · Modified 21/12/2025 08:41
Sectors (8)
- Telecommunications targets
- Ministries of foreign affairs targets
- Government targets
- Education targets
- NGO targets
- Defense targets
- Defense ministries (including the military) targets
- Energy targets
Countries (7)
- Ukraine targets
- British Indian Ocean Territory targets
- Russian Federation targets
- Philippines targets
- Pakistan targets
- Afghanistan targets
- India targets
Indicators (100)
-
9b97e740b65bc609210f095cd9407c990a9f71f580f001ea07300228c5256d62related -
1c1bb64e38c3fbe1a8f0dcb94ded96b332296bcbf839de438a4838fb43b20af3related -
8168dc0baea6a74120fbabea261e83377697cb5f9726a2514f38ed04b46c56c8related -
7c7fad6b9ecb1e770693a6c62e0cc4183f602b892823f4a451799376be915912related -
b262292e049ee75d235164df98fa8ed09a9e2a30c5432623856bafd4bd44d801related -
hcdh-tunisie.orgrelated -
bd7dbaf91ba162b6623292ebcdd2768c5d87e518240fe8ca200a81e9c7f01d76related -
www.baltdefcol.orgrelated -
http://www.simplifiedhomesales.com/wp-includes/images/index.phprelated -
mail.lechateaudelatour.frrelated -
b6abbeab6e000036c6cdffc57c096d796397263e280ea264eba73ac5bab39441related -
f9ebf6aeb3f0fb0c29bd8f3d652476cd1fe8bd9a0c11cb15c43de33bbce0bf68related -
portal.northernfruit.comrelated -
009406c1c7c0b289a25d44dfaa8364633d9b71df5f3c7a65deec1ef00a8c2ebbrelated -
crusider.tkrelated -
aba8b59281faa8c1c43a4ca7af075edd3e3516d3cef058a1f43b093177b8f83crelated -
mail.kzp.bgrelated -
http://files.philbendeck.com/article/related -
branter.tkrelated -
duke6.tkrelated -
arianeconseil.onlinerelated -
0fc624aa9656a8bc21731bfc47fd7780da38a7e8ad7baf1529ccd70a5bb07852related -
www.berlinguas.comrelated -
b376a3a6bae73840e70b2fa3df99d881def9250b42b6b8b0458d0445ddfbc044related -
5e122ff3066b6ef2a89295df925431c151f1713708c99772687a30c3204064bdrelated -
baltdefcol.webredirect.orgrelated -
493e5fae191950b901764868b065ddddffa4f4c9b497022ee2f998b4a94f0fc2related -
gaismustudija.lvrelated -
e33580ae3df9d27d7cfb7b8f518a2704e55c92dd74cbbab8ef58ddfd36524cc8related -
http://files.philbendeck.com/help/related -
7a7d11adbcb740323eb52b097f535cfa5c281bf07a4d5c4afb0c5182fa4ffd1brelated -
www.adelaida.uarelated -
mail.lebsack.derelated -
https://icw2016.coachfederation.cz/wp-includes/images/wp/related -
http://octoberoctopus.co.za/wp-includes/sitemaps/web/related -
134919151466c9292bdcb7c24c32c841a5183d880072b0ad5e8b3a3a830afef8related -
2164d54c415b48e906ad972a14d45c82af7cab814c6cf11729a994249690ed97related -
mail.arlingtonhousing.usrelated -
dfdc0318f3dc5ba3f960b1f338b638cd9645856d2a2af8aa33ea0f9979a9ca4crelated -
www.balletmaniacs.comrelated -
http://sansaispa.com/wp-includes/images/gallery/related -
https://185.126.255.132/requestor.phprelated -
caduff-sa.chjeepcarlease.comrelated -
mail.aet.in.uarelated -
19b7ddd3b06794abe593bf533d88319711ca15bb0a08901b4ab7e52aab015452related -
13fafb1ae2d5de024e68f2e2fc820bc79ef0690c40dbfd70246bcc394c52ea20related -
ee8ef58f3bf0dab066eb608cb0f167b1585e166bf4730858961c192860ceffe9related -
mail.numina.mdrelated -
https://socprime.com/blog/uac-0149-attack-detection-hackers-launch-a-targeted-attack-against-the-armed-forces-of-ukraine-as-cert-ua-reports/related -
564b2a3083e55933e4ce68b87c5e268c88d58f7ab41839e5a6e0c728a58e9cf2related -
29b1da7b17a7ba3e730e6927058d0554a8bc81bdef88e364097fab0bb1950edcrelated -
809cc49746fd6e5892b9a00a1fef8467f9e80db2related -
manager.surro.amrelated -
files.philbendeck.comrelated -
a3170c32c09fc85cdda778a5c20a3dab144b6d1dd9996ba8340866e0081c7642related -
thedarktower.av.master.dns-cloud.netrelated -
1c97f92a144ac17e35c0e40dc89e12211ef5a7d5eb8db57ab093987ae6f3b9dcrelated -
carleasingguru.comrelated -
www.gallen.firelated -
http://www.bombheros.com/wp-content/languages/index.phprelated -
sansaispa.comrelated -
a56703e72f79b4ec72b97c53fbd8426eb6515e3645cb02e7fc99aaaea515273erelated -
octoberoctopus.co.zarelated -
https://plagnol-charpentier.fr/wp-includes/random_compat/random_compata0zW7Qrelated -
connectotels.netrelated -
https://citactica.com/wp-content/wp-login.phprelated -
http://files.philbendeck.com/related -
6536b6b50aa1f6899ffa90aaf4b1b67c0ae0f6c0441016f5308b37c12141c61drelated -
00352afc7e7863530e4d68be35ae8b60261fc57560167645697b7bfc0ac0e93drelated -
wkoinfo.webredirect.orgrelated -
185.126.255.132related -
c039ec6622393f9324cacbf8cfaba3b7a41fe6929812ce3bd5d79b0fdedc884arelated -
http://files.philbendeck.com/file/related -
cac4d4364d20fa343bf681f6544b31995a57d8f69ee606c4675db60be5ae8775related -
87663affd147065d08d4fe76d9a18b0d7d85fab68cf9f5ac96cfdfff3f27ffd2related -
http://mtsoft.hol.es/wp-content/gallery/related -
d26ac1a90f3b3f9e11491f789e55abe5b7d360df77c91a597e775f6db49902earelated -
atomydoc.kgrelated -
20691ff3c9474cfd7bf6fa3f8720eb7326e6f87f64a1f190861589c1e7397fa5related -
ced8891ea8d87005de989f25f0f94634d1fc70ebb37302cf21aa0c0b0e13350frelated -
69908f05b436bd97baae56296bf9b9e734486516f9bb9938c2b8752e152315d4related -
fc68026b83392aa227e9adf9c71289cb51ba03427f6de67a73ae872e19ef6ff9related -
16860fc685ea0dee91e65e253062153ac6c886fdd73a3020c266601f58038a61related -
08803510089c8832df3f6db57aded7bfd2d91745e7dd44985d4c9cb9bd5fd1d2related -
lakihelppi.comrelated -
f3aaa091fdbc8772fb7bd3a81665f4d33c3b62bf98caad6fee4424654ba26429related -
jadlactnato.webredirect.orgrelated -
http://mail.aet.in.ua/outlook/api/logoff.aspxrelated -
b93484683014aca8e909c9b5648d8f0ac21a45d0c193f6ca40f0b01d2464c1c4related -
2b969111dd1968d47b02d6390c92fb622cd03570b02ecf9215031ff03611a2b7related -
00256c7fd9a36c6a4805c467b15b3a72dbac2e6dbd12abe7d768f20ce6c8f09frelated -
046f11a6c561e46e6bf199ab7f50e74a4d2aaead68cdbd6ce44b37b5b4964758related -
7c4ef30bd1b5cb690d2603e33264768e3b42752660c79979a5db80816dfb2ad2related -
29314f3cd73b81eda7bd90c66f659235e6bb900e499c9cc7057d10a9083a0b94related -
b51105c56d1bf8f98b7e924aa5caded8322d037745a128781fa0bc23841d1e70related -
kav-certificates.inforelated -
https://brauche-it.de/wp-includes/blocks/blocksu9ky0orelated -
15f5e4808549ff67a79f84e23659da912ebbc1dc7c7b100c12b72384a27e412arelated -
7d5794ad91351c7c5d7fbad8e83e3b71a09baac65fb09ca75d8d18339d24a46frelated -
http://files.philbendeck.com/about/related
Vulnerabilities (CVE) (2)
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with …
- Attack vector
- Local
- Published
- 23/04/2024
- Modified
- 21/12/2025
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, …
- Attack vector
- Local
- Complexity
- Low
- Published
- 30/05/2025
- Modified
- 02/04/2026
Tool (12)
-
certutil usesThe MITRE Corporation Confidence 100
[certutil](https://attack.mitre.org/software/S0160) is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. (Citation: TechNet Certutil)
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
Reg usesThe MITRE Corporation Confidence 100
[Reg](https://attack.mitre.org/software/S0075) is a Windows utility used to interact with the Windows Registry. It can be used at the command-line interface to query, add, modify, and remove information. (Citation: …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
netstat usesThe MITRE Corporation Confidence 100
[netstat](https://attack.mitre.org/software/S0104) is an operating system utility that displays active TCP connections, listening ports, and network statistics. (Citation: TechNet Netstat)
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
Arp usesThe MITRE Corporation Confidence 100
[Arp](https://attack.mitre.org/software/S0099) displays and modifies information about a system's Address Resolution Protocol (ARP) cache. (Citation: TechNet Arp)
Published 31/05/2017 23:33 · Modified 27/03/2026 01:07 -
NBTscan usesThe MITRE Corporation Confidence 100
[NBTscan](https://attack.mitre.org/software/S0590) is an open source tool that has been used by state groups to conduct internal reconnaissance within a compromised network.(Citation: Debian nbtscan Nov 2019)(Citation: SecTools nbtscan June …
Published 17/03/2021 16:26 · Modified 27/03/2026 01:07 -
Net usesThe MITRE Corporation Confidence 100
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
nbtstat usesThe MITRE Corporation Confidence 100
[nbtstat](https://attack.mitre.org/software/S0102) is a utility used to troubleshoot NetBIOS name resolution. (Citation: TechNet Nbtstat)
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
IronNetInjector usesThe MITRE Corporation Confidence 100
[IronNetInjector](https://attack.mitre.org/software/S0581) is a [Turla](https://attack.mitre.org/groups/G0010) toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including [ComRAT](https://attack.mitre.org/software/S0126).(Citation: Unit …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
Mimikatz usesThe MITRE Corporation Confidence 100
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
Tasklist usesThe MITRE Corporation Confidence 100
The [Tasklist](https://attack.mitre.org/software/S0057) utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
PsExec usesThe MITRE Corporation Confidence 100
[PsExec](https://attack.mitre.org/software/S0029) is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.(Citation: Russinovich Sysinternals)(Citation: SANS …
Published 31/05/2017 23:32 · Modified 27/03/2026 01:07 -
Systeminfo usesThe MITRE Corporation Confidence 100
[Systeminfo](https://attack.mitre.org/software/S0096) is a Windows utility that can be used to gather detailed information about a computer. (Citation: TechNet Systeminfo)
Published 31/05/2017 23:33 · Modified 27/03/2026 01:07