Turla — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    Turla

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    Turla
    🛰️
    Espionage & Satellite C2 (illustrative)
    Also known asSecret Blizzard · Venomous Bear · Waterbug · Uroburos · KRYPTON · Snake
    Formationc. 1996–2004
    TypeAdvanced persistent threat (state-sponsored)
    PurposeCyber-espionage, Political intelligence
    Target SectorsGovernment, Embassies, Military, Research
    Alleged parent org.FSB (Center 16)
    Attribution confidenceHigh
    Status● Active
    Notable toolsSnake (Uroburos), Carbon, Gazer, TinyTurla

    Turla, also identified as Secret Blizzard, Venomous Bear, and Waterbug, is one of the world’s most sophisticated and longest-running Russian state-sponsored cyber-espionage groups. Attributed to Russia’s Federal Security Service (FSB), specifically Center 16, Turla has been active for over two decades, evolving from early operations like “Moonlight Maze.”[1]

    The group is characterized by its extreme technical stealth and focus on high-value intelligence. Turla is renowned for its use of unconventional Command and Control (C2) mechanisms, including the hijacking of commercial satellite internet links to mask the location of its servers and the “fourth-party” hijacking of infrastructure belonging to other APT groups.[2]

    Aliases used by other vendors:
    Secret Blizzard (Microsoft) · Venomous Bear (CrowdStrike) · Waterbug (Symantec) · KRYPTON (Mandiant) · Group 88 (Talos) · Iron Hunter (Secureworks)

    Overview

    Turla primarily targets government entities, diplomatic missions, and military organizations. Unlike “loud” actors who utilize destructive wipers, Turla prioritizes long-term persistence, often remaining inside compromised networks for years to systematically exfiltrate sensitive geopolitical intelligence.[1]

    Attribution

    In 2023, the U.S. government and international partners publicly linked Turla to the FSB’s Center 16. This attribution was reinforced by “Operation Medusa,” a joint effort to dismantle the group’s “Snake” malware infrastructure, which had been utilized by the FSB for nearly 20 years.[3]

    “Turla represents the ‘patient hunter’ of the cyber world. Their ability to repurpose the tools of their victims and hide in the noise of satellite traffic demonstrates a level of tradecraft few others can match.”
    — Global Intelligence Briefing, 2023[4]

    Targets and victimology

    • Diplomatic Corps — Embassies and Ministries of Foreign Affairs worldwide.
    • Research & Education — High-tech research institutes and universities in the EU and North America.
    • Defense — NATO-aligned military contractors and aerospace agencies.

    Operational History

    PeriodKey Developments
    1996–2000Moonlight Maze: Extensive breaches of U.S. government systems, widely seen as Turla’s progenitor.
    2008Agent.btz: A worm that successfully breached U.S. Central Command via USB drives.
    2014–2016Discovery of the “Uroburos” (Snake) rootkit; first observations of satellite C2 hijacking.
    2019–2020“Infrastructure Hijacking”: Turla was caught using the C2 infrastructure of the Iranian group OilRig.
    2023Operation Medusa: FBI-led disruption of the Snake malware global network.

    Custom Toolset

    NameDescription
    Snake (Uroburos)A highly complex kernel-mode rootkit used for covert data exfiltration.
    CarbonA modular second-stage backdoor used for lateral movement and reconnaissance.
    GazerStealthy C++ backdoor that uses digital certificates from legitimate companies to bypass security.
    TinyTurlaA minimalist backdoor used as a fail-safe backup if primary implants are detected.
    KazuarA .NET-based multi-platform backdoor with extensive info-stealing capabilities.

    Satellite C2 & Stealth

    Turla is famous for utilizing Digital Video Broadcasting-Satellite (DVB-S) hijacking. By spoofing the IP addresses of legitimate satellite internet users, the group can receive data from compromised machines via satellite downlink. Because this traffic is broadcast over a wide geographic area, it is nearly impossible to physically locate the group’s actual C2 servers.[2]

    Tactics and Techniques

    TacticTechnique IDDescription
    Initial AccessT1189Drive-by Compromise: Using “watering hole” attacks on government websites.
    Defense EvasionT1014Rootkit: Deep system integration to hide files and network connections.
    C2T1008Fallback Channels: Using multiple redundant backdoors to maintain access.

    References

    1. Kaspersky Lab, “The Epic Turla Operation” (2014).
    2. ESET Research, “Diplomatic Spectacles: Turla’s focus on European foreign affairs” (2020).
    3. U.S. Department of Justice, “Justice Department Announces Shutdown of Stealthy ‘Snake’ Malware Network” (May 2023).
    4. Microsoft Threat Intelligence, “Profile of Secret Blizzard” (2024).
    Categories: Advanced persistent threats · Russian state-sponsored hacking · FSB · Cyber-espionage · Satellite Hijacking
    This page was last updated August 2026. Data compiled from global cybersecurity research archives.