Turla

G0010

Threat group.View on attack.mitre.org

About this group

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.

Techniques used68

Procedure examples68

TechniqueProcedure example
T1005
Data from Local System

Turla RPC backdoors can upload files from victim machines.

T1007
System Service Discovery

Turla surveys a system upon check-in to discover running services and associated processes using the tasklist /svc command.

T1012
Query Registry

Turla surveys a system upon check-in to discover information in the Windows Registry with the reg query command. Turla has also retrieved PowerShell payloads hidden in Registry keys as well as checking keys associated with null session named pipes .

T1016
System Network Configuration Discovery

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.

T1016.001
Internet Connection Discovery

Turla has used tracert to check internet connectivity.

T1018
Remote System Discovery

Turla surveys a system upon check-in to discover remote systems on a local network using the net view and net view /DOMAIN commands. Turla has also used net group "Domain Computers" /domain, net group "Domain Controllers" /domain, and net group "Exchange Servers" /domain to enumerate domain computers, including the organization's DC and Exchange Server.

T1021.002
SMB/Windows Admin Shares

Turla used net use commands to connect to lateral systems within a network.

T1025
Data from Removable Media

Turla RPC backdoors can collect files from USB thumb drives.

T1027.005
Indicator Removal from Tools

Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe.

T1027.010
Command Obfuscation

Turla has used encryption (including salted 3DES via PowerSploit's Out-EncryptedScript.ps1), random variable names, and base64 encoding to obfuscate PowerShell commands and payloads.

T1027.011
Fileless Storage

Turla has used the Registry to store encrypted and encoded payloads.

T1036.005
Match Legitimate Resource Name or Location

Turla has named components of LunarWeb to mimic Zabbix agent logs.

T1049
System Network Connections Discovery

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands. Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.

T1055
Process Injection

Turla has also used PowerSploit's Invoke-ReflectivePEInjection.ps1 to reflectively load a PowerShell payload into a random process on the victim system.

T1055.001
Dynamic-link Library Injection

Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges.

View all 68 procedure examples

Software30

Show 6 more

Campaigns0

None recorded.

References5

  1. CrowdStrike VENOMOUS BEAR Open source
    Meyers, A. (2018, March 12). Meet CrowdStrike’s Adversary of the Month for March: VENOMOUS BEAR. Retrieved May 16, 2018.
  2. ESET Gazer Aug 2017 Open source
    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.
  3. ESET Turla Mosquito Jan 2018 Open source
    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.
  4. Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023 Open source
    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.
  5. Kaspersky Turla Open source
    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.