Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Turla

🇷🇺Turla

🇷🇺 Turla is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: State. We map 26 detection use cases to this actor across 102 MITRE ATT&CK techniques, with 7 threat-intel articles citing them. Active in our corpus from 2020-11-13 to 2026-07-27.

crit 3high 1med 3
View full actor card → All threat actors MITRE ATT&CK group spec (G0010) ↗
26Use cases
7Articles
102Techniques
36IOCs

Known aliases

TurlaSnakeVenomous BearWaterbugUroburosKryptonSecret BlizzardIRON HUNTERGroup 88WhiteBearBELUGASTURGEON

Top techniques

All other tracked techniques

T1003.001 · LSASS MemoryT1005 · Data from Local SystemT1007 · System Service DiscoveryT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1016.001 · Internet Connection DiscoveryT1018 · Remote System DiscoveryT1021.002 · SMB/Windows Admin SharesT1025 · Data from Removable MediaT1027 · Obfuscated Files or InformationT1027.005 · Indicator Removal from ToolsT1027.010 · Command ObfuscationT1027.011 · Fileless StorageT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1055.013 · Process DoppelgängingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1069.001 · Local GroupsT1069.002 · Domain GroupsT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.003 · Mail ProtocolsT1071.004 · DNST1074.001 · Local Data StagingT1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1090 · ProxyT1090.001 · Internal ProxyT1102 · Web ServiceT1102.001 · Dead Drop ResolverT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1110 · Brute ForceT1112 · Modify RegistryT1120 · Peripheral Device DiscoveryT1124 · System Time DiscoveryT1132.001 · Standard EncodingT1134.001 · Token Impersonation/TheftT1134.002 · Create Process with TokenT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1189 · Drive-by CompromiseT1201 · Password Policy DiscoveryT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1211 · Exploitation for StealthT1213.006 · DatabasesT1218 · System Binary Proxy ExecutionT1218.005 · MshtaT1218.011 · Rundll32T1219 · Remote Access ToolsT1518.001 · Security Software DiscoveryT1539 · Steal Web Session CookieT1546.003 · Windows Management Instrumentation Event SubscriptionT1546.013 · PowerShell ProfileT1547.001 · Registry Run Keys / Startup FolderT1547.004 · Winlogon Helper DLLT1553.006 · Code Signing Policy ModificationT1555.004 · Windows Credential ManagerT1560.001 · Archive via UtilityT1562.001 · T1562.001T1564.004 · NTFS File AttributesT1564.012 · File/Path ExclusionsT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1572 · Protocol TunnelingT1574.002 · T1574.002T1583.006 · Web ServicesT1584.003 · Virtual Private ServerT1584.004 · ServerT1584.006 · Web ServicesT1587.001 · MalwareT1588.001 · MalwareT1588.002 · ToolT1615 · Group Policy DiscoveryT1620 · Reflective Code LoadingT1685 · Disable or Modify Tools

Detection use cases (26)

Turla (Snake/Venomous Bear) PowerShell in-memory loader staging an encrypted payload blob in the registry (ComRAT/Kazuar) AI · profile SΣDD Turla (Secret Blizzard/ComRAT) C2 over legitimate cloud/webmail services from a non-browser process AI · profile SDD Cruciferra persistence: Run key 'putty' value pointing to non-PuTTY binary Bespoke Cruciferra BYOVD: vulnerable driver (GoFlyDrv.sys) load for EDR tampering Bespoke Cruciferra loader side-load DLLs and Remcos logs.dat drop Bespoke Cruciferra known-sample SHA256 execution/write Bespoke Cruciferra C2 beacon to known IOC domains/IPs (incl. .gu.cc cluster) Bespoke Process Ghosting: executable created then deleted while backing a live process Bespoke Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal 1Password failed sign-in burst MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match

Threat-intel articles (7)

Tracked indicators

Domains (30)

0zbqnac1t4dv2t2wuodv1m.c 1kkkkddd.com almacensantangel.com faeytrdeaw.gu.cc figyuyrqwr.gu.cc fuaytrwese.love gatuso.duckdns.org govtop.one hfyuayustrv.gu.cc hsahyteiows.gu.cc ikkkkddd.com jiayingjing.com jsiruytrawey.gu.cc kawosyetw.gu.cc kawuuterta.gu.cc kkxqbh.top laiwutrencr.gu.cc lasiduutfe.gu.cc maisytawe.gu.cc nciyeyrawoe.gu.cc nviuawusye.gu.cc nvsieyrrawe.gu.cc pmcjsuyraw.gu.cc qeuasytua.love simaqz.com +5 more

IP addresses (6)

117.44.201.119 118.107.0.197 204.194.48.250 223.26.63.40 27.50.54.191 89.34.90.99

CVEs (3)

CVE-2024-42009 CVE-2025-8088 CVE-2025-9491