Turla
Also tracked as IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.
- Documented techniques
- 68
- Assessed origin
- Russia
- Assessed motivation
- Espionage
- First seen
- 2004
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development7
initial access2
execution7
privilege escalation3
credential access2
discovery18
- T1007 System Service Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1016.001 Internet Connection Discovery
- T1018 Remote System Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1069.001 Local Groups
- T1069.002 Domain Groups
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1120 Peripheral Device Discovery
- T1124 System Time Discovery
- T1201 Password Policy Discovery
- T1518.001 Security Software Discovery
- T1615 Group Policy Discovery
lateral movement2
collection4
command and control7
exfiltration1
defense impairment3
stealth10
- T1027.005 Indicator Removal from Tools
- T1027.010 Command Obfuscation
- T1027.011 Fileless Storage
- T1036.005 Match Legitimate Resource Name or Location
- T1055 Process Injection
- T1055.001 Dynamic-link Library Injection
- T1078.003 Local Accounts
- T1134.002 Create Process with Token
- T1140 Deobfuscate/Decode Files or Information
- T1564.012 File/Path Exclusions
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.