A 2014 Guardian article described Turla as: 'Dubbed the Turla hackers, initial intelligence had indicated western powers were key targets, but it was ...

Threat Actor Profile

Turla

State-sponsored threat group originating from RU. Suspected sponsor: Russian Federation. Known to target Government, Military. Uses 92 known MITRE ATT&CK techniques.

92 TTPs Mapped 2 Industries Tracked Real-Time Alerts

Actor Overview

Origin Country
RU
Suspected Sponsor
Russian Federation
Incident Types
Espionage
Known Techniques
92 TTPs

Target Industries

GovernmentMilitary

Suspected Victims

FranceRomaniaKazakhstanPolandTajikistanRussiaUnited StatesSaudi ArabiaGermanyIndiaBelarusNetherlandsIranUzbekistanIraq

MITRE ATT&CK Techniques

T1134T1134.002T1087T1087.001T1087.002T1583T1583.006T1071T1071.001T1071.003T1560T1560.001T1547T1547.001T1547.004 +77 more

Related Threat Reports

Premium
APT Campaign Analysis - Q4 2025Dec 2025
New Tactics Observed in WildDec 2025
Infrastructure Mapping ReportDec 2025
Stay Updated

Get alerts when new intel on Turla is published.

Actor Details

Primary Name
Turla
Known Aliases
Snake, VENOMOUS Bear, Group 88, Waterbug, WRAITH, Uroburos, Pfinet, TAG_0530, KRYPTON, Hippo Team, Pacifier APT, Popeye, SIG23, IRON HUNTER, MAKERSMARK, ATK13, G0010, ITG12, Blue Python, SUMMIT, UNC4210, Secret Blizzard, UAC-0144, UAC-0024, UAC-0003
Data Source
Precursor Intelligence
Need API Access?

Integrate threat actor data into your SIEM or SOAR.

View Plans →