RussiaWidely attributedActiveMITRE G0010

Turla

Coverage omission — Eastern

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
4.7
Moderate signal strength
Mentions6
Sources2
High conf.4
Last seenMay 2026
First observed
2017-05-31
Last active
Active
Origin
Russia — widely attributed to FSB (Federal Security Service)
Aliases
13
Techniques
68
Campaigns
1
Russia — widely attributed to FSB (Federal Security Service)high confidence
TargetsGovernmentMilitaryDefenceDiplomatic
RegionsEuUsMiddle EastCisNato

Attribution signals

6 mentions · 2 sources
#1attributed tohigh
Malware
mstic
May 2026

"Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard"

#2developed byhigh
Malware
wechat-qax-ti
May 2026

"Kazuar malware continuously developed by Secret Blizzard has evolved from traditional backdoor to modular peer-to-peer botnet"

#3known forhigh
Victimology
security-affairs
May 2026

"The hacking group is known for its attacks targeting government, diplomatic, and defense sectors in Europe and Central Asia, as well as endpoints previously breached by Aqua Blizzard (aka Actinium and Gamaredon) to support the Kremlin's strategic objectives."

#4very likelyhigh
VictimologyGeopolitical
mstic
May 2026

"The threat actor has historically targeted organizations in the government and diplomatic sector in Europe and Central Asia, as well as systems in Ukraine previously compromised by Aqua Blizzard, very likely for the purpose of obtaining information supporting Russia's foreign policy and military objectives."

#5assessed to be affiliatedmoderate
HUMINT
security-affairs
May 2026

"According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Russia-nexus actor is assessed to be affiliated with Center 16 of Russia's Federal Security Service (FSB)."

#6Russia-linkedmoderate
Malware
security-affairs
May 2026

"Russia-linked APT group Turla upgraded its Kazuar backdoor into a modular peer-to-peer botnet designed for stealth and persistent access to infected systems."

Hedge terms observed

assessed to be affiliatedattributed todeveloped byknown forRussia-linkedvery likely