Skip to content
RussiaState-SponsoredActiveMITRE G0010Malpedia ↗

Turla

FSB Centre 16. The oldest continuously active espionage group on record — known for hijacking satellite links and stealing other nations' operations outright.

ATTRIBUTED TORussia › FSB — Federal Security Service › Centre 16

Open MITRE Navigator layer ↗Download profile JSON
Active
1996–present
Motivation
Espionage
Aliases
13
Exploited CVEs
3
ATT&CK techniques
14
Cited sources
11

Overview

Turla is the most technically inventive espionage actor in the public record, and among the oldest — its lineage traces to the Moonlight Maze intrusions against U.S. defence networks in 1996, making the operation older than most of the analysts who track it.

Its distinguishing habit is parasitism. Rather than build its own infrastructure, Turla takes other people's. It has hijacked satellite internet downlinks — exploiting the fact that legacy one-way satellite traffic is unencrypted and broadcast over a wide footprint — to receive exfiltrated data at an untraceable, constantly shifting location. In 2019 the UK NCSC and NSA documented Turla commandeering the infrastructure and implants of Iran's OilRig, running operations from inside another nation's espionage program so that victims and analysts would attribute the activity to Tehran. In 2024 Microsoft and Lumen documented the same technique applied to a Pakistani group's C2 servers.

Its Snake implant — known variously as Uroburos and Turla — is a peer-to-peer kernel-level rootkit refined over nearly two decades, with a bespoke encrypted network layer that made it exceptionally hard to detect in transit. The FBI dismantled the global Snake network in May 2023 through Operation MEDUSA, using a purpose-built tool that issued Snake's own self-destruct command.

Turla's other signature is the LightNeuron backdoor, an Exchange transport agent that operates at the mail-server level with the ability to read, modify, block, and originate email as any user in the organisation.

Attribution

Down to the named unit where public evidence supports it.

RussiaFSB — Federal Security ServiceCentre 16Confirmed

Military Unit 71330, FSB 16th Centre (signals intelligence)

Attributed to FSB Centre 16 by the U.S. Department of Justice in May 2023, announced alongside Operation MEDUSA — the court-authorised, worldwide takedown of the Snake implant network. The DOJ statement identifies Turla as an FSB unit that has operated Snake for nearly twenty years and locates it within Centre 16, also known as Military Unit 71330. The five-country joint advisory published the same day provides corroborating technical detail.

Attributing sources

Cross-vendor naming crosswalk

13 designators across 11 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • Turla

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Secret BlizzardFormerly KRYPTON
  • KRYPTONRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Venomous Bear

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • Turla

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • IRON HUNTER

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Pensive Ursa

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • Group 88

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

ESET Research

index ↗
  • Turla

Descriptive names, frequently derived from the group's flagship malware family.

Kaspersky GReAT

index ↗
  • Turla
  • UroburospartialNames the flagship rootkit; frequently used for the group itself

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Symantec (Broadcom)

index ↗
  • Waterbug

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • Snake / FSB Centre 16

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesGermanyFranceUkraineBelgiumAustriaPolandRomaniaKazakhstanAfghanistan

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Snake / Uroburosmalware

Peer-to-peer kernel rootkit with a bespoke encrypted transport, developed and maintained for nearly two decades. Dismantled by FBI Operation MEDUSA in May 2023.

Malpedia ↗
ComRATbackdoor

Long-lived implant, later versions using Gmail's web interface for C2 — commands arrive as attachments to a draft mailbox.

Malpedia ↗
LightNeuronbackdoor

Microsoft Exchange transport agent operating at mail-server level: reads, modifies, blocks, and composes mail as any user in the organisation.

Malpedia ↗
Kazuarbackdoor

.NET backdoor with an unusual API-driven command interface; code overlaps with SUNBURST prompted analysis of shared lineage.

Malpedia ↗
TinyTurla / TinyTurla-NGbackdoor

Minimal service-DLL backdoor deployed as an emergency fallback when primary access is lost.

Malpedia ↗
Crutchbackdoor

Dropbox-based exfiltration framework used against EU foreign ministries.

Carbonframework

Modular espionage framework with a peer-to-peer internal network for reaching air-gapped-adjacent hosts.

Malpedia ↗
HyperStackbackdoor

Named-pipe RPC backdoor for controlling hosts deep inside segmented networks.

Satellite C2 hijackingutility

Abuse of unencrypted one-way satellite downlinks to receive exfiltrated data at an untraceable, shifting location.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Turla
CVE-2019-19781KEVransomware9.81 Feb 2020Citrix ADC exploitation for initial access to government networks in Europe.SRCSymantec
CVE-2019-0604KEVransomware9.81 Apr 2019SharePoint deserialisation exploited to install web shells on government servers, providing durable access.SRCSymantec
CVE-2017-11882KEVransomware7.81 Jan 2018Equation Editor exploit in lure documents delivering the Turla downloader stage.SRCESET

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 14 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
14 techniques across 7 tactics · 9 with actor-specific notes

Resource Development

2

Persistence

1

Defense Evasion

3

Lateral Movement

1

Campaign timeline

  1. Snake Network and Operation MEDUSA

    A peer-to-peer kernel rootkit operated for nearly two decades against government and diplomatic targets in over 50 countries. Dismantled by the FBI in May 2023 through Operation MEDUSA, using a purpose-built tool that issued Snake's own self-destruct command against the implant network.

    GovernmentDiplomaticDefenseThink Tanks & Academia

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.