Also known as IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, SUMMIT, UAC-0194, VENOMOUS BEAR
Tracked asG0010
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.
Turla has been publicly attributed by CISA to Center 16 of Russia's Federal Security Service (FSB)
GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR may be developed in-part by a common developer or team, with active development occurring in tandem
K1MORPHER string obfuscation mechanism observed in STOCKSTAY in April 2025 and later identified in samples of KAZUAR in June 2025
Operational playbook
Facts
Uses STOCKSTAY at multiple distinct stages of operations: early stage with hard-coded configuration passwords, and later stage following reconnaissance with environmental keying
Deploying STOCKSTAY alongside KAZUAR during active operations, assessed as possible testing of new capabilities in environments where existing access may be remediated
Initial access and identity targets
Facts
Malicious RDP configuration files in phishing emails
Malicious HTA files hosting STOCKSTAY downloader
Compromised email accounts belonging to Ukrainian universities
Compromised diplomatic education platforms for phishing and malicious RDP distribution
Compromised government services and infrastructure in Ukraine for payload deployment
Capabilities and evasion
Facts
File operations: delete, list directories, retrieve files with specific extensions, upload files, extract ZIP archives
Command execution: execute processes with configurable timeout, capture system information via WMI
Screen capture functionality
Multi-task processing capability
Proxy-aware network communication
Environmental keying for configuration protection using hostname, domain name, and username hashes
Infrastructure patterns
Facts
Uses secure WebSocket connections for C2 communication
Leverages third-party hosting platforms such as Render platform
Utilizes compromised WordPress sites during various stages of operations
GitHub repository containing Python implementation of victim-facing STOCKSTAY WebSocket server controller
Multi-hop C2 infrastructure similar to KAZUAR architecture
Compromised Ukrainian government services and IT company infrastructure for payload hosting
WebSocket server stores messages in SQLite3 database (weather_data1.db)
Communication and pressure channels
Facts
IPC communication via WM_COPYDATA messages between STOCKSTAY components
RSA 4096-bit encryption of outbound data prior to WebSocket transmission
Unique 4096-bit RSA key pair generated on first execution for each implant
Server-side component uses base64-encoding and JSON serialization for message format
Observed targeting
Facts
Consistent focus on western Ministries of Foreign Affairs and defense organizations
Significant proportion of STOCKSTAY operations targeted at Government or Military organizations within Ukraine
Early development samples identified in European nations including Italy, Netherlands, Poland, and Germany
Targeting of entities associated with foreign affairs ministry in Europe
Affinity for integrating academia and diplomacy into infrastructure and lure content
Use of educational institution names in file naming and phishing domains
Named victims
Organizations
Government and military organizations in Ukraine
Entities with interest in Italian foreign policy
Defender guidance
Facts
Monitor for WebSocket connections to unusual domains, particularly those resembling legitimate cryptocurrency or financial services
Hunt for .NET applications masquerading as stock market tools, PDF viewers, or calculator utilities
Detect suspicious RDP file attachments in phishing emails, particularly those impersonating academic or diplomatic institutions
Monitor for IPC communication using WM_COPYDATA messages between suspicious .NET processes
Examine encrypted configuration files in legitimate file locations that contain suspicious hex-encoded data
Monitor GitHub repositories for suspicious MSI file uploads with product names like 'DiplomacyEduAI'
Track deployments of multiple .NET components (STOCKBROKER, STOCKMARKET, STOCKTRADER) operating together
Reported detail
Facts
Turla deployed STOCKSTAY, a multi-component .NET backdoor, against Ukrainian government and military organizations and European foreign affairs entities since at least December 2022
STOCKSTAY uses secure WebSocket C2 communication and modular architecture separating network communication, orchestration, and task execution into distinct components
The malware employs environmental keying for configuration protection and masquerades as benign applications like stock market tools and PDF viewers
GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR share common developers based on overlapping code, architecture, and obfuscation techniques introduced in 2025
The group has been observed deploying STOCKSTAY via malicious RDP files in phishing campaigns and leveraging compromised Ukrainian and European infrastructure for payload hosting
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
Indicator49 indicators cataloged
Types: sha256.
Cataloged
IdentityAlias: IRON HUNTER
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Group 88
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Waterbug
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: WhiteBear
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Snake
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Krypton
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Venomous Bear
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Secret Blizzard
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: BELUGASTURGEON
Reviewed identity mapping approved on this date.
Cataloged
IdentityTracking identifier: G0010
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: SUMMIT
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Secret Blizzard
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: VENOMOUS BEAR
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: UAC-0194
Reviewed identity mapping approved on this date.
First observed
CVECVE-2025-8088 linked to this actor
The Latest Addition to Turla’s Intelligence Gathering Apparatus | Google Cloud Blog
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
TurlaCanonical Name
BELUGASTURGEONAlias
Group 88Alias
IRON HUNTERAlias
KryptonAlias
Secret BlizzardAlias
SnakeAlias
Venomous BearAlias
WaterbugAlias
WhiteBearAlias
SUMMITAlias
UAC-0194Alias
G0010Tracking Id
Loading CVEs, techniques, indicators, malware, victims, and activity...