← Back to all threat actors

Turla

Also known as IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, SUMMIT, UAC-0194, VENOMOUS BEAR
Tracked as G0010

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.

How we source and review actor profiles
Attributed nexus
RU
Status
Active

Threat intelligence assessment

At a glance

Facts

  • Turla is one of the oldest known cyber espionage groups with suspected activity dating back to at least 2004
  • STOCKSTAY is a multi-component .NET backdoor communicating via secure WebSocket connection using the websocket-sharp library

Activity timeline

Facts

  • STOCKSTAY has been continuously developed and deployed since at least December 2022
  • Earliest suspected development activity identified December 2022 based on websocket-sharp.dll timestamps
  • STOCKSTAY deployed against government and military organizations in Ukraine and entities with interest in Italian foreign policy
  • Operations observed in Ukraine (January 2024, March-August 2025), Italy (February 2024), Germany (September 2023), Netherlands (December 2023), Poland (May 2025)

Attribution assessment

Facts

  • Turla has been publicly attributed by CISA to Center 16 of Russia's Federal Security Service (FSB)
  • GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR may be developed in-part by a common developer or team, with active development occurring in tandem
  • K1MORPHER string obfuscation mechanism observed in STOCKSTAY in April 2025 and later identified in samples of KAZUAR in June 2025

Operational playbook

Facts

  • Uses STOCKSTAY at multiple distinct stages of operations: early stage with hard-coded configuration passwords, and later stage following reconnaissance with environmental keying
  • Deploying STOCKSTAY alongside KAZUAR during active operations, assessed as possible testing of new capabilities in environments where existing access may be remediated

Initial access and identity targets

Facts

  • Malicious RDP configuration files in phishing emails
  • Malicious HTA files hosting STOCKSTAY downloader
  • Compromised email accounts belonging to Ukrainian universities
  • Compromised diplomatic education platforms for phishing and malicious RDP distribution
  • Compromised government services and infrastructure in Ukraine for payload deployment

Capabilities and evasion

Facts

  • File operations: delete, list directories, retrieve files with specific extensions, upload files, extract ZIP archives
  • Registry operations: read, write, delete registry values
  • Command execution: execute processes with configurable timeout, capture system information via WMI
  • Screen capture functionality
  • Multi-task processing capability
  • Proxy-aware network communication
  • Environmental keying for configuration protection using hostname, domain name, and username hashes

Infrastructure patterns

Facts

  • Uses secure WebSocket connections for C2 communication
  • Leverages third-party hosting platforms such as Render platform
  • Utilizes compromised WordPress sites during various stages of operations
  • GitHub repository containing Python implementation of victim-facing STOCKSTAY WebSocket server controller
  • Multi-hop C2 infrastructure similar to KAZUAR architecture
  • Compromised Ukrainian government services and IT company infrastructure for payload hosting
  • WebSocket server stores messages in SQLite3 database (weather_data1.db)

Communication and pressure channels

Facts

  • IPC communication via WM_COPYDATA messages between STOCKSTAY components
  • RSA 4096-bit encryption of outbound data prior to WebSocket transmission
  • Unique 4096-bit RSA key pair generated on first execution for each implant
  • Server-side component uses base64-encoding and JSON serialization for message format

Observed targeting

Facts

  • Consistent focus on western Ministries of Foreign Affairs and defense organizations
  • Significant proportion of STOCKSTAY operations targeted at Government or Military organizations within Ukraine
  • Early development samples identified in European nations including Italy, Netherlands, Poland, and Germany
  • Targeting of entities associated with foreign affairs ministry in Europe
  • Affinity for integrating academia and diplomacy into infrastructure and lure content
  • Use of educational institution names in file naming and phishing domains

Named victims

Organizations

  • Government and military organizations in Ukraine
  • Entities with interest in Italian foreign policy

Defender guidance

Facts

  • Monitor for WebSocket connections to unusual domains, particularly those resembling legitimate cryptocurrency or financial services
  • Hunt for .NET applications masquerading as stock market tools, PDF viewers, or calculator utilities
  • Detect suspicious RDP file attachments in phishing emails, particularly those impersonating academic or diplomatic institutions
  • Monitor for IPC communication using WM_COPYDATA messages between suspicious .NET processes
  • Examine encrypted configuration files in legitimate file locations that contain suspicious hex-encoded data
  • Monitor GitHub repositories for suspicious MSI file uploads with product names like 'DiplomacyEduAI'
  • Track deployments of multiple .NET components (STOCKBROKER, STOCKMARKET, STOCKTRADER) operating together

Reported detail

Facts

  • Turla deployed STOCKSTAY, a multi-component .NET backdoor, against Ukrainian government and military organizations and European foreign affairs entities since at least December 2022
  • STOCKSTAY uses secure WebSocket C2 communication and modular architecture separating network communication, orchestration, and task execution into distinct components
  • The malware employs environmental keying for configuration protection and masquerades as benign applications like stock market tools and PDF viewers
  • GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR share common developers based on overlapping code, architecture, and obfuscation techniques introduced in 2025
  • The group has been observed deploying STOCKSTAY via malicious RDP files in phishing campaigns and leveraging compromised Ukrainian and European infrastructure for payload hosting

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
Indicator49 indicators cataloged

Types: sha256.

Cataloged
IdentityAlias: IRON HUNTER

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Group 88

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Waterbug

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: WhiteBear

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Snake

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Krypton

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Venomous Bear

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Secret Blizzard

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BELUGASTURGEON

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0010

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: SUMMIT

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Secret Blizzard

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: VENOMOUS BEAR

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UAC-0194

Reviewed identity mapping approved on this date.

First observed
CVECVE-2025-8088 linked to this actor

The Latest Addition to Turla’s Intelligence Gathering Apparatus | Google Cloud Blog

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

TurlaCanonical Name
BELUGASTURGEONAlias
Group 88Alias
IRON HUNTERAlias
KryptonAlias
Secret BlizzardAlias
SnakeAlias
Venomous BearAlias
WaterbugAlias
WhiteBearAlias
SUMMITAlias
UAC-0194Alias
G0010Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...