{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "turla",
    "slug": "turla",
    "name": "Turla",
    "shortName": "Turla",
    "country": "Russia",
    "countryCode": "RU",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "1996",
    "prominence": 91,
    "mitreGroupId": "G0010",
    "malpediaSlug": "turla",
    "tagline": "FSB Centre 16. The oldest continuously active espionage group on record — known for hijacking satellite links and stealing other nations' operations outright.",
    "bio": "Turla is the most technically inventive espionage actor in the public record, and among the oldest — its lineage traces to the Moonlight Maze intrusions against U.S. defence networks in 1996, making the operation older than most of the analysts who track it.\n\nIts distinguishing habit is parasitism. Rather than build its own infrastructure, Turla takes other people's. It has hijacked satellite internet downlinks — exploiting the fact that legacy one-way satellite traffic is unencrypted and broadcast over a wide footprint — to receive exfiltrated data at an untraceable, constantly shifting location. In 2019 the UK NCSC and NSA documented Turla commandeering the infrastructure and implants of Iran's OilRig, running operations from inside another nation's espionage program so that victims and analysts would attribute the activity to Tehran. In 2024 Microsoft and Lumen documented the same technique applied to a Pakistani group's C2 servers.\n\nIts Snake implant — known variously as Uroburos and Turla — is a peer-to-peer kernel-level rootkit refined over nearly two decades, with a bespoke encrypted network layer that made it exceptionally hard to detect in transit. The FBI dismantled the global Snake network in May 2023 through Operation MEDUSA, using a purpose-built tool that issued Snake's own self-destruct command.\n\nTurla's other signature is the LightNeuron backdoor, an Exchange transport agent that operates at the mail-server level with the ability to read, modify, block, and originate email as any user in the organisation.",
    "attribution": {
      "sponsor": "Russia",
      "service": "FSB — Federal Security Service",
      "unit": "Centre 16",
      "unitDetail": "Military Unit 71330, FSB 16th Centre (signals intelligence)",
      "confidence": "confirmed",
      "summary": "Attributed to FSB Centre 16 by the U.S. Department of Justice in May 2023, announced alongside Operation MEDUSA — the court-authorised, worldwide takedown of the Snake implant network. The DOJ statement identifies Turla as an FSB unit that has operated Snake for nearly twenty years and locates it within Centre 16, also known as Military Unit 71330. The five-country joint advisory published the same day provides corroborating technical detail.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Justice Department Announces Court-Authorized Disruption of Snake Malware Network Controlled by Russia's FSB",
          "url": "https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-snake-malware-network-controlled",
          "date": "2023-05-09"
        },
        {
          "org": "CISA / FBI / NSA and international partners",
          "title": "Hunting Russian Intelligence 'Snake' Malware (AA23-129A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a",
          "date": "2023-05-09"
        },
        {
          "org": "NCSC-UK / NSA",
          "title": "Turla group exploits Iranian APT to expand coverage of victims",
          "url": "https://www.ncsc.gov.uk/news/turla-group-exploits-iran-apt-to-expand-coverage-of-victims",
          "date": "2019-10-21"
        }
      ]
    },
    "motivations": [
      "espionage"
    ],
    "targetSectors": [
      "Government",
      "Diplomatic",
      "Defense",
      "Think Tanks & Academia",
      "Technology",
      "Telecommunications",
      "Energy",
      "Media & Journalism"
    ],
    "targetCountries": [
      "United States",
      "Germany",
      "France",
      "Ukraine",
      "Belgium",
      "Austria",
      "Poland",
      "Romania",
      "Kazakhstan",
      "Afghanistan"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Turla",
        "url": "https://attack.mitre.org/groups/G0010/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Secret Blizzard",
        "correlation": "exact",
        "note": "Formerly KRYPTON"
      },
      {
        "org": "microsoft",
        "name": "KRYPTON",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Venomous Bear",
        "url": "https://www.crowdstrike.com/adversaries/venomous-bear/",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "Turla",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "IRON HUNTER",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Pensive Ursa",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "Turla",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "Uroburos",
        "correlation": "partial",
        "note": "Names the flagship rootkit; frequently used for the group itself"
      },
      {
        "org": "eset",
        "name": "Turla",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Waterbug",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Snake / FSB Centre 16",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "Group 88",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "Snake / Uroburos",
        "type": "malware",
        "custom": true,
        "description": "Peer-to-peer kernel rootkit with a bespoke encrypted transport, developed and maintained for nearly two decades. Dismantled by FBI Operation MEDUSA in May 2023.",
        "malpediaSlug": "win.snake"
      },
      {
        "name": "ComRAT",
        "type": "backdoor",
        "custom": true,
        "description": "Long-lived implant, later versions using Gmail's web interface for C2 — commands arrive as attachments to a draft mailbox.",
        "malpediaSlug": "win.comrat"
      },
      {
        "name": "LightNeuron",
        "type": "backdoor",
        "custom": true,
        "description": "Microsoft Exchange transport agent operating at mail-server level: reads, modifies, blocks, and composes mail as any user in the organisation.",
        "malpediaSlug": "win.lightneuron"
      },
      {
        "name": "Kazuar",
        "type": "backdoor",
        "custom": true,
        "description": ".NET backdoor with an unusual API-driven command interface; code overlaps with SUNBURST prompted analysis of shared lineage.",
        "malpediaSlug": "win.kazuar"
      },
      {
        "name": "TinyTurla / TinyTurla-NG",
        "type": "backdoor",
        "custom": true,
        "description": "Minimal service-DLL backdoor deployed as an emergency fallback when primary access is lost.",
        "malpediaSlug": "win.tinyturla"
      },
      {
        "name": "Crutch",
        "type": "backdoor",
        "custom": true,
        "description": "Dropbox-based exfiltration framework used against EU foreign ministries."
      },
      {
        "name": "Carbon",
        "type": "framework",
        "custom": true,
        "description": "Modular espionage framework with a peer-to-peer internal network for reaching air-gapped-adjacent hosts.",
        "malpediaSlug": "win.carbon"
      },
      {
        "name": "HyperStack",
        "type": "backdoor",
        "custom": true,
        "description": "Named-pipe RPC backdoor for controlling hosts deep inside segmented networks."
      },
      {
        "name": "Satellite C2 hijacking",
        "type": "utility",
        "custom": true,
        "description": "Abuse of unencrypted one-way satellite downlinks to receive exfiltrated data at an untraceable, shifting location."
      }
    ],
    "techniques": [
      {
        "tCode": "T1584.004",
        "name": "Compromise Infrastructure: Server",
        "tactic": "Resource Development",
        "note": "Hijacking of other actors' C2 infrastructure, including OilRig and Storm-0156"
      },
      {
        "tCode": "T1608.004",
        "name": "Stage Capabilities: Drive-by Target",
        "tactic": "Resource Development",
        "note": "Long-running watering holes on embassy and ministry websites"
      },
      {
        "tCode": "T1189",
        "name": "Drive-by Compromise",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1014",
        "name": "Rootkit",
        "tactic": "Defense Evasion",
        "note": "Snake kernel-mode driver"
      },
      {
        "tCode": "T1505.002",
        "name": "Server Software Component: Transport Agent",
        "tactic": "Persistence",
        "note": "LightNeuron on Exchange"
      },
      {
        "tCode": "T1205.001",
        "name": "Traffic Signaling: Port Knocking",
        "tactic": "Command and Control"
      },
      {
        "tCode": "T1102.002",
        "name": "Web Service: Bidirectional Communication",
        "tactic": "Command and Control",
        "note": "ComRAT using Gmail draft folders"
      },
      {
        "tCode": "T1090.003",
        "name": "Proxy: Multi-hop Proxy",
        "tactic": "Command and Control",
        "note": "Satellite downlink hijacking for untraceable exfiltration"
      },
      {
        "tCode": "T1001.002",
        "name": "Data Obfuscation: Steganography",
        "tactic": "Command and Control",
        "note": "Commands hidden in image and video files"
      },
      {
        "tCode": "T1027.003",
        "name": "Obfuscated Files or Information: Steganography",
        "tactic": "Defense Evasion"
      },
      {
        "tCode": "T1074.001",
        "name": "Data Staged: Local Data Staging",
        "tactic": "Collection"
      },
      {
        "tCode": "T1091",
        "name": "Replication Through Removable Media",
        "tactic": "Lateral Movement",
        "note": "USB propagation to reach isolated networks"
      },
      {
        "tCode": "T1553.006",
        "name": "Subvert Trust Controls: Code Signing Policy Modification",
        "tactic": "Defense Evasion",
        "note": "Exploiting a vulnerable VirtualBox driver to load unsigned code"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2019-19781",
        "firstExploited": "2020-02-01",
        "usage": "Citrix ADC exploitation for initial access to government networks in Europe.",
        "source": {
          "org": "Symantec",
          "title": "Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments",
          "url": "https://symantec-enterprise-blogs.security.com/threat-intelligence/waterbug-espionage-governments",
          "date": "2019-06-20"
        }
      },
      {
        "cveId": "CVE-2019-0604",
        "firstExploited": "2019-04-01",
        "usage": "SharePoint deserialisation exploited to install web shells on government servers, providing durable access.",
        "source": {
          "org": "Symantec",
          "title": "Waterbug: Espionage Group Rolls Out Brand-New Toolset",
          "url": "https://symantec-enterprise-blogs.security.com/threat-intelligence/waterbug-espionage-governments",
          "date": "2019-06-20"
        }
      },
      {
        "cveId": "CVE-2017-11882",
        "firstExploited": "2018-01-01",
        "usage": "Equation Editor exploit in lure documents delivering the Turla downloader stage.",
        "source": {
          "org": "ESET",
          "title": "Turla Outlook Backdoor: Analysis of an unusual Turla backdoor",
          "url": "https://www.welivesecurity.com/wp-content/uploads/2018/08/Eset-Turla-Outlook-Backdoor.pdf",
          "date": "2018-08-22"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt34",
        "type": "operational-overlap",
        "confidence": "high",
        "note": "Turla hijacked OilRig's infrastructure and implants to run its own operations under Iranian cover — documented jointly by NCSC-UK and NSA in October 2019."
      },
      {
        "relatedActorId": "apt29",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both conduct strategic espionage for Russian services against overlapping diplomatic targets; FSB and SVR respectively."
      },
      {
        "relatedActorId": "gamaredon",
        "type": "same-sponsor",
        "confidence": "high",
        "note": "Both FSB. Turla has been observed deploying its own implants onto hosts Gamaredon compromised first, using the noisier group as a scouting layer."
      }
    ],
    "reports": [
      {
        "org": "Kaspersky GReAT",
        "title": "Satellite Turla: APT Command and Control in the Sky",
        "url": "https://securelist.com/satellite-turla-apt-command-and-control-in-the-sky/72081/",
        "date": "2015-09-09"
      },
      {
        "org": "ESET",
        "title": "LightNeuron: A Turla backdoor operating at the Exchange transport level",
        "url": "https://www.welivesecurity.com/2019/05/07/turla-lightneuron-email-too-far/",
        "date": "2019-05-07"
      },
      {
        "org": "NCSC-UK / NSA",
        "title": "Advisory: Turla group exploits Iranian APT to expand coverage of victims",
        "url": "https://www.ncsc.gov.uk/news/turla-group-exploits-iran-apt-to-expand-coverage-of-victims",
        "date": "2019-10-21"
      },
      {
        "org": "Kaspersky GReAT",
        "title": "Penquin's Moonlit Maze — tracing Turla's lineage to the 1996 Moonlight Maze intrusions",
        "url": "https://securelist.com/penquins-moonlit-maze/77883/",
        "date": "2017-04-03"
      },
      {
        "org": "Microsoft Threat Intelligence",
        "title": "Secret Blizzard compromising other threat actors' infrastructure to target Ukraine",
        "url": "https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/",
        "date": "2024-12-11"
      }
    ],
    "campaigns": [
      {
        "id": "snake-medusa",
        "actorId": "turla",
        "name": "Snake Network and Operation MEDUSA",
        "date": "2004-01-01",
        "endDate": "2023-05-09",
        "significance": "major",
        "targetSectors": [
          "Government",
          "Diplomatic",
          "Defense",
          "Think Tanks & Academia"
        ],
        "targetCountries": [
          "United States",
          "Germany",
          "France",
          "Ukraine",
          "Belgium",
          "Austria"
        ],
        "cveIds": [],
        "summary": "A peer-to-peer kernel rootkit operated for nearly two decades against government and diplomatic targets in over 50 countries. Dismantled by the FBI in May 2023 through Operation MEDUSA, using a purpose-built tool that issued Snake's own self-destruct command against the implant network.",
        "sources": [
          {
            "org": "U.S. Department of Justice",
            "title": "Court-Authorized Disruption of Snake Malware Network Controlled by Russia's FSB",
            "url": "https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-snake-malware-network-controlled",
            "date": "2023-05-09"
          },
          {
            "org": "CISA and partners",
            "title": "AA23-129A: Hunting Russian Intelligence Snake Malware",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a",
            "date": "2023-05-09"
          }
        ]
      }
    ],
    "flag": "🇷🇺",
    "profile": "/apt/turla/"
  }
}