Resource Development
2 techniques·derived
Hijacking of other actors' C2 infrastructure, including OilRig and Storm-0156. Long-running watering holes on embassy and ministry websites.
FSB Centre 16. The oldest continuously active espionage group on record — known for hijacking satellite links and stealing other nations' operations outright.
ATTRIBUTED TORussia › FSB — Federal Security Service › Centre 16
Turla is the most technically inventive espionage actor in the public record, and among the oldest — its lineage traces to the Moonlight Maze intrusions against U.S. defence networks in 1996, making the operation older than most of the analysts who track it.
Its distinguishing habit is parasitism. Rather than build its own infrastructure, Turla takes other people's. It has hijacked satellite internet downlinks — exploiting the fact that legacy one-way satellite traffic is unencrypted and broadcast over a wide footprint — to receive exfiltrated data at an untraceable, constantly shifting location. In 2019 the UK NCSC and NSA documented Turla commandeering the infrastructure and implants of Iran's OilRig, running operations from inside another nation's espionage program so that victims and analysts would attribute the activity to Tehran. In 2024 Microsoft and Lumen documented the same technique applied to a Pakistani group's C2 servers.
Its Snake implant — known variously as Uroburos and Turla — is a peer-to-peer kernel-level rootkit refined over nearly two decades, with a bespoke encrypted network layer that made it exceptionally hard to detect in transit. The FBI dismantled the global Snake network in May 2023 through Operation MEDUSA, using a purpose-built tool that issued Snake's own self-destruct command.
Turla's other signature is the LightNeuron backdoor, an Exchange transport agent that operates at the mail-server level with the ability to read, modify, block, and originate email as any user in the organisation.
Down to the named unit where public evidence supports it.
Military Unit 71330, FSB 16th Centre (signals intelligence)
Attributed to FSB Centre 16 by the U.S. Department of Justice in May 2023, announced alongside Operation MEDUSA — the court-authorised, worldwide takedown of the Snake implant network. The DOJ statement identifies Turla as an FSB unit that has operated Snake for nearly twenty years and locates it within Centre 16, also known as Military Unit 71330. The five-country joint advisory published the same day provides corroborating technical detail.
Attributing sources
13 designators across 11 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Descriptive names, frequently derived from the group's flagship malware family.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Peer-to-peer kernel rootkit with a bespoke encrypted transport, developed and maintained for nearly two decades. Dismantled by FBI Operation MEDUSA in May 2023.
Malpedia ↗Long-lived implant, later versions using Gmail's web interface for C2 — commands arrive as attachments to a draft mailbox.
Malpedia ↗Microsoft Exchange transport agent operating at mail-server level: reads, modifies, blocks, and composes mail as any user in the organisation.
Malpedia ↗.NET backdoor with an unusual API-driven command interface; code overlaps with SUNBURST prompted analysis of shared lineage.
Malpedia ↗Minimal service-DLL backdoor deployed as an emergency fallback when primary access is lost.
Malpedia ↗Dropbox-based exfiltration framework used against EU foreign ministries.
Modular espionage framework with a peer-to-peer internal network for reaching air-gapped-adjacent hosts.
Malpedia ↗Named-pipe RPC backdoor for controlling hosts deep inside segmented networks.
Abuse of unencrypted one-way satellite downlinks to receive exfiltrated data at an untraceable, shifting location.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by Turla | ||
|---|---|---|---|---|
| CVE-2019-19781KEVransomware | 9.8 | Citrix ADC / GatewayCitrix | 1 Feb 2020 | Citrix ADC exploitation for initial access to government networks in Europe.SRCSymantec ↗ |
| CVE-2019-0604KEVransomware | 9.8 | Microsoft SharePointMicrosoft | 1 Apr 2019 | SharePoint deserialisation exploited to install web shells on government servers, providing durable access.SRCSymantec ↗ |
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jan 2018 | Equation Editor exploit in lure documents delivering the Turla downloader stage.SRCESET ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
Hijacking of other actors' C2 infrastructure, including OilRig and Storm-0156. Long-running watering holes on embassy and ministry websites.
2 techniques·derived
Drive-by Compromise, Spearphishing Attachment.
1 technique·derived
LightNeuron on Exchange.
3 techniques·derived
Snake kernel-mode driver. Exploiting a vulnerable VirtualBox driver to load unsigned code.
1 technique·derived
USB propagation to reach isolated networks.
1 technique·derived
Local Data Staging.
4 techniques·derived
ComRAT using Gmail draft folders. Satellite downlink hijacking for untraceable exfiltration. Commands hidden in image and video files.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Hijacking of other actors' C2 infrastructure, including OilRig and Storm-0156
Long-running watering holes on embassy and ministry websites
LightNeuron on Exchange
Snake kernel-mode driver
Exploiting a vulnerable VirtualBox driver to load unsigned code
USB propagation to reach isolated networks
A peer-to-peer kernel rootkit operated for nearly two decades against government and diplomatic targets in over 50 countries. Dismantled by the FBI in May 2023 through Operation MEDUSA, using a purpose-built tool that issued Snake's own self-destruct command against the implant network.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Turla hijacked OilRig's infrastructure and implants to run its own operations under Iranian cover — documented jointly by NCSC-UK and NSA in October 2019.
Both conduct strategic espionage for Russian services against overlapping diplomatic targets; FSB and SVR respectively.
Both FSB. Turla has been observed deploying its own implants onto hosts Gamaredon compromised first, using the noisier group as a scouting layer.
Curated links to the reports that established what is known about this group.