🇷🇺Turla
🇷🇺 Turla is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: State. We map 26 detection use cases to this actor across 102 MITRE ATT&CK techniques, with 7 threat-intel articles citing them. Active in our corpus from 2020-11-13 to 2026-07-27.
crit 3high 1med 3
26Use cases
7Articles
102Techniques
36IOCs
Known aliases
TurlaSnakeVenomous BearWaterbugUroburosKryptonSecret BlizzardIRON HUNTERGroup 88WhiteBearBELUGASTURGEON
Top techniques
All other tracked techniques
T1003.001 · LSASS MemoryT1005 · Data from Local SystemT1007 · System Service DiscoveryT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1016.001 · Internet Connection DiscoveryT1018 · Remote System DiscoveryT1021.002 · SMB/Windows Admin SharesT1025 · Data from Removable MediaT1027 · Obfuscated Files or InformationT1027.005 · Indicator Removal from ToolsT1027.010 · Command ObfuscationT1027.011 · Fileless StorageT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1055.013 · Process DoppelgängingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1069.001 · Local GroupsT1069.002 · Domain GroupsT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.003 · Mail ProtocolsT1071.004 · DNST1074.001 · Local Data StagingT1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1090 · ProxyT1090.001 · Internal ProxyT1102 · Web ServiceT1102.001 · Dead Drop ResolverT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1110 · Brute ForceT1112 · Modify RegistryT1120 · Peripheral Device DiscoveryT1124 · System Time DiscoveryT1132.001 · Standard EncodingT1134.001 · Token Impersonation/TheftT1134.002 · Create Process with TokenT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1189 · Drive-by CompromiseT1201 · Password Policy DiscoveryT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1211 · Exploitation for StealthT1213.006 · DatabasesT1218 · System Binary Proxy ExecutionT1218.005 · MshtaT1218.011 · Rundll32T1219 · Remote Access ToolsT1518.001 · Security Software DiscoveryT1539 · Steal Web Session CookieT1546.003 · Windows Management Instrumentation Event SubscriptionT1546.013 · PowerShell ProfileT1547.001 · Registry Run Keys / Startup FolderT1547.004 · Winlogon Helper DLLT1553.006 · Code Signing Policy ModificationT1555.004 · Windows Credential ManagerT1560.001 · Archive via UtilityT1562.001 · T1562.001T1564.004 · NTFS File AttributesT1564.012 · File/Path ExclusionsT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1572 · Protocol TunnelingT1574.002 · T1574.002T1583.006 · Web ServicesT1584.003 · Virtual Private ServerT1584.004 · ServerT1584.006 · Web ServicesT1587.001 · MalwareT1588.001 · MalwareT1588.002 · ToolT1615 · Group Policy DiscoveryT1620 · Reflective Code LoadingT1685 · Disable or Modify Tools
Detection use cases (26)
Turla (Snake/Venomous Bear) PowerShell in-memory loader staging an encrypted payload blob in the registry (ComRAT/Kazuar) Turla (Secret Blizzard/ComRAT) C2 over legitimate cloud/webmail services from a non-browser process Cruciferra persistence: Run key 'putty' value pointing to non-PuTTY binary Cruciferra BYOVD: vulnerable driver (GoFlyDrv.sys) load for EDR tampering Cruciferra loader side-load DLLs and Remcos logs.dat drop Cruciferra known-sample SHA256 execution/write Cruciferra C2 beacon to known IOC domains/IPs (incl. .gu.cc cluster) Process Ghosting: executable created then deleted while backing a live process Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process 1Password failed sign-in burst Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 MinutesThreat-intel articles (7)
med MuddyWater: Snakes by the riverbank · 2025-12-02
crit ESET APT Activity Report Q2 2025–Q3 2025 · 2025-11-06
Tracked indicators
Domains (30)
0zbqnac1t4dv2t2wuodv1m.c 1kkkkddd.com almacensantangel.com faeytrdeaw.gu.cc figyuyrqwr.gu.cc fuaytrwese.love gatuso.duckdns.org govtop.one hfyuayustrv.gu.cc hsahyteiows.gu.cc ikkkkddd.com jiayingjing.com jsiruytrawey.gu.cc kawosyetw.gu.cc kawuuterta.gu.cc kkxqbh.top laiwutrencr.gu.cc lasiduutfe.gu.cc maisytawe.gu.cc nciyeyrawoe.gu.cc nviuawusye.gu.cc nvsieyrrawe.gu.cc pmcjsuyraw.gu.cc qeuasytua.love simaqz.com +5 moreIP addresses (6)
117.44.201.119 118.107.0.197 204.194.48.250 223.26.63.40 27.50.54.191 89.34.90.99CVEs (3)
CVE-2024-42009 CVE-2025-8088 CVE-2025-9491