G0010 · 69 ATT&CK techniques · 3 correlated reports

Turla

Aliases: IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.

Open interactive actor investigation

ATT&CK techniques

T1584.006
Web Services
T1112
Modify Registry
T1069.001
Local Groups
T1140
Deobfuscate/Decode Files or Information
T1588.002
Tool
T1059.007
JavaScript
T1134.002
Create Process with Token
T1562.001
Disable or Modify Tools
T1059.005
Visual Basic
T1546.013
PowerShell Profile
T1583.006
Web Services
T1055.001
Dynamic-link Library Injection
T1105
Ingress Tool Transfer
T1555.004
Windows Credential Manager
T1090
Proxy
T1068
Exploitation for Privilege Escalation
T1615
Group Policy Discovery
T1049
System Network Connections Discovery
T1106
Native API
T1071.003
Mail Protocols
T1021.002
SMB/Windows Admin Shares
T1547.001
Registry Run Keys / Startup Folder
T1005
Data from Local System
T1012
Query Registry
T1007
System Service Discovery
T1110
Brute Force
T1570
Lateral Tool Transfer
T1189
Drive-by Compromise
T1584.004
Server
T1087.002
Domain Account
T1564.012
File/Path Exclusions
T1120
Peripheral Device Discovery
T1567.002
Exfiltration to Cloud Storage
T1102.002
Bidirectional Communication
T1071.001
Web Protocols
T1124
System Time Discovery
T1087.001
Local Account
T1204.001
Malicious Link
T1090.001
Internal Proxy
T1546.003
Windows Management Instrumentation Event Subscription
T1560.001
Archive via Utility
T1059.003
Windows Command Shell
T1057
Process Discovery
T1016
System Network Configuration Discovery
T1587.001
Malware
T1025
Data from Removable Media
T1518.001
Security Software Discovery
T1059.001
PowerShell
T1027.010
Command Obfuscation
T1059.006
Python
T1213
Data from Information Repositories
T1018
Remote System Discovery
T1588.001
Malware
T1069.002
Domain Groups
T1027.011
Fileless Storage
T1547.004
Winlogon Helper DLL
T1553.006
Code Signing Policy Modification
T1566.002
Spearphishing Link
T1016.001
Internet Connection Discovery
T1102
Web Service
T1082
System Information Discovery
T1584.003
Virtual Private Server
T1036.005
Match Legitimate Name or Location
T1055
Process Injection
T1078.003
Local Accounts
T1201
Password Policy Discovery
T1083
File and Directory Discovery
T1027.005
Indicator Removal from Tools
T1566.001
Spearphishing Attachment

Correlated CTI and IR reports

Continue the investigation