Turla, Waterbug, Venomous Bear

Description

Turla is a Russian-based threat group that has infected victims in over 45 countries, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies since 2004. Heightened activity was seen in mid-2015. Turla is known for conducting watering hole and spear-phishing campaigns and leveraging in-house tools and malware. Turla’s espionage platform is mainly used against Windows machines, but has also been seen used against macOS and Linux machines.

Turla has been known to also infiltrate malicious infrastructure from other APT groups such as Transparent Tribe, APT 36 in 2022.

Names

NameName-Giver
TurlaKaspersky
WaterbugSymantec
Venomous BearCrowdStrike
Group 88Talos
SIG2NSA
SIG15NSA
SIG23NSA
Iron HunterSecureWorks
CTG-8875SecureWorks
Pacifier APTBitdefender
ATK 13Thales
ITG12IBM
MakersmarkESET
KryptonMicrosoft
BelugasturgeonAccenture
Popeye?
Wraith?
TAG-0530Recorded Future
UNC4210Mandiant
SUMMITGoogle
Secret BlizzardMicrosoft
Pensive UrsaPalo Alto
Blue PythonPWC

Country

State-sponsored, FSB Centre 16L: Radio-Electronic Intelligence on Communications Facilities, Post Number 71330

Motivation

  • Information theft and espionage

First Seen

1996

Observed Sectors

Observed Countries

Tools

Operations

Information

Mitre Attack

Other Information

Uuid

ebff5365-ae36-4e47-a310-28c1f3be0b3a

Last Card Change

2024-12-27