Back to ThreatBox
ThreatBox · Threat Actor Attribution

Turla

a.k.a. Snake, Venomous Bear, Waterbug, Krypton, Secret Blizzard
Espionage (state-sponsored) Russia (FSB — Center 16) First seen 1996

Turla is one of the oldest and most sophisticated Russian state-sponsored groups, attributed to the FSB. Famous for satellite-link C2 (piggy-backing on unencrypted downstream satellite IPs), the Snake modular framework (dismantled by FBI Operation MEDUSA in May 2023), and stealthy Outlook backdoors that use the Exchange webmail protocol as C2. Ties back to the 2008 Agent.BTZ intrusion of US DOD SIPRNet.

Targeted sectors
GovernmentDiplomaticMilitaryResearch
Targeted regions
Global (100+ countries)

Known TTPs (4)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2008-11
    Agent.BTZ compromise of US DOD SIPRNet
  2. 2015-09
    Satellite-link C2 technique publicly exposed (Kaspersky)
  3. 2023-05
    FBI Operation MEDUSA — Snake framework dismantled
  4. 2023-12
    Kazuar backdoor v2 activity against Ukraine defense targets

References

End of dossier · Turla
Back to ThreatBox

Made with Emergent