Turla is a Russia-linked APT group that has conducted long-term cyber espionage against government, diplomatic, military, research, and technology targets across multiple countries since at least 2008. Recent campaigns in 2026 included STOCKSTAY backdoor activity and attacks on French entities, showing continued focus on stealthy intelligence collection and strategic access. #Turla #STOCKSTAY #France
Keypoints
- Turla is a Russia-linked APT group active since at least 2008 and focused on espionage.
- The group targets high-value organizations such as governments, diplomatic entities, military groups, research bodies, and technology firms.
- In April–June 2026, Turla expanded activity across strategic technology and enterprise environments, including email, VPN, proxy, OS, and web-facing systems.
- In July 2026, CYFIRMA reported suspected STOCKSTAY backdoor use against government organizations, Western foreign ministries, and defence entities in Ukraine and Italy.
- Also in July 2026, researchers reported a Turla intrusion campaign against French organizations in diplomatic, defence, justice, and technology sectors.
- Turla continues to rely on stealth, covert persistence, encrypted C2, legitimate infrastructure, and long-term footholds to support intelligence collection.
- The group maintains a broad malware ecosystem, including Uroburos, Comrat, Epic, Kazuar, Carbon, Gazer, and Tinyturla-NG.
MITRE Techniques
- [T1587.001] Develop Capabilities: Malware – Turla develops custom malware to support espionage operations (‘custom toolsets’ and ‘sophisticated malware’).
- [T1583.006] Acquire Infrastructure: Web Services – The group uses web services as part of its infrastructure (‘encrypted command-and-control (C2) infrastructure’ and internet-facing technologies).
- [T1584.003] Compromise Infrastructure: Virtual Private Server – Turla compromises VPS resources to host infrastructure (‘Compromise Infrastructure: Virtual Private Server’).
- [T1584.004] Compromise Infrastructure: Server – The actor compromises servers to extend access and C2 reach (‘Compromise Infrastructure: Server’).
- [T1584.006] Compromise Infrastructure: Web Services – The group abuses web services for covert infrastructure (‘Compromise Infrastructure: Web Services’).
- [T1588.002] Obtain Capabilities: Tool – Turla acquires tools to improve operations (‘Obtain Capabilities: Tool’).
- [T1588.001] Obtain Capabilities: Malware – The group obtains malware for operations (‘Obtain Capabilities: Malware’).
- [T1189] Drive-by Compromise – Initial access may occur through drive-by compromise (‘Drive-by Compromise’).
- [T1078.003] Valid Accounts: Local Accounts – Turla uses valid local accounts to gain or maintain access (‘Valid Accounts: Local Accounts’).
- [T1566.002] Phishing: Spearphishing Link – The group uses spearphishing links for access (‘Spearphishing Link’).
- [T1106] Native API – Malware execution leverages native APIs (‘Native API’).
- [T1204.001] User Execution: Malicious Link – Victims may be tricked into opening malicious links (‘Malicious Link’).
- [T1059.003] Command and Scripting Interpreter: Windows Command Shell – The actor uses cmd.exe or similar shell commands (‘Windows Command Shell’).
- [T1059.006] Command and Scripting Interpreter: Python – Turla uses Python for execution and automation (‘Python’).
- [T1059.007] Command and Scripting Interpreter: JavaScript – JavaScript is used to run malicious logic (‘JavaScript’).
- [T1059.005] Command and Scripting Interpreter: Visual Basic – The group uses Visual Basic for scripting and execution (‘Visual Basic’).
- [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – Persistence is maintained via run keys/startup folder (‘Registry Run Keys / Startup Folder’).
- [T1547.004] Boot or Logon Autostart Execution: Winlogon Helper DLL – Turla uses Winlogon helper DLLs for persistence (‘Winlogon Helper DLL’).
- [T1112] Modify Registry – The group modifies the registry to change settings and persistence (‘Modify Registry’).
- [T1546.003] Event Triggered Execution: Windows Management Instrumentation Event Subscription – Turla uses WMI event subscriptions for trigger-based execution (‘Windows Management Instrumentation Event Subscription’).
- [T1546.013] Event Triggered Execution: PowerShell Profile – PowerShell profiles are abused for execution on login (‘PowerShell Profile’).
- [T1068] Exploitation for Privilege Escalation – The actor exploits vulnerabilities to gain higher privileges (‘Exploitation for Privilege Escalation’).
- [T1055] Process Injection – Turla injects code into other processes to evade detection (‘Process Injection’).
- [T1055.001] Process Injection: Dynamic-link Library Injection – DLL injection is used to run malicious code inside trusted processes (‘Dynamic-link Library Injection’).
- [T1134.002] Access Token Manipulation: Create Process with Token – The group uses tokens to create processes with elevated or alternate privileges (‘Create Process with Token’).
- [T1140] Deobfuscate/Decode Files or Information – Malware decodes obfuscated content during execution (‘Deobfuscate/Decode Files or Information’).
- [T1564.012] Hide Artifacts: File/Path Exclusions – Turla hides files or paths to avoid detection (‘File/Path Exclusions’).
- [T1036.005] Masquerading: Match Legitimate Resource Name or Location – The actor disguises files or resources as legitimate items (‘Match Legitimate Resource Name or Location’).
- [T1027.005] Obfuscated Files or Information: Indicator Removal from Tools – Turla removes indicators from tools to frustrate analysis (‘Indicator Removal from Tools’).
- [T1027.010] Obfuscated Files or Information: Command Obfuscation – Commands are obfuscated to reduce visibility (‘Command Obfuscation’).
- [T1027.011] Obfuscated Files or Information: Fileless Storage – The group uses fileless storage to minimize forensic artifacts (‘Fileless Storage’).
- [T1685] Disable or Modify Tools – Turla disables or alters defensive tools (‘Disable or Modify Tools’).
- [T1553.006] Subvert Trust Controls: Code Signing Policy Modification – The actor modifies code-signing policy to weaken trust controls (‘Code Signing Policy Modification’).
- [T1110] Brute Force – Password guessing is used to access accounts (‘Brute Force’).
- [T1555.004] Credentials from Password Stores: Windows Credential Manager – Credentials are harvested from Windows Credential Manager (‘Windows Credential Manager’).
- [T1083] File and Directory Discovery – The group searches for files and directories (‘File and Directory Discovery’).
- [T1615] Group Policy Discovery – Turla checks group policy settings (‘Group Policy Discovery’).
- [T1201] Password Policy Discovery – The actor discovers password policy details (‘Password Policy Discovery’).
- [T1120] Peripheral Device Discovery – The group enumerates connected devices (‘Peripheral Device Discovery’).
- [T1069.001] Permission Groups Discovery: Local Groups – Turla enumerates local groups (‘Local Groups’).
- [T1069.002] Permission Groups Discovery: Domain Groups – Turla enumerates domain groups (‘Domain Groups’).
- [T1057] Process Discovery – The actor lists running processes (‘Process Discovery’).
- [T1018] Remote System Discovery – Remote systems are identified for follow-on movement (‘Remote System Discovery’).
- [T1087.001] Account Discovery: Local Account – Local accounts are enumerated (‘Local Account’).
- [T1087.002] Account Discovery: Domain Account – Domain accounts are enumerated (‘Domain Account’).
- [T1518.001] Software Discovery: Security Software Discovery – Turla identifies security software present on hosts (‘Security Software Discovery’).
- [T1007] System Service Discovery – The group enumerates services on the system (‘System Service Discovery’).
- [T1082] System Information Discovery – Turla gathers host information (‘System Information Discovery’).
- [T1012] Query Registry – The actor queries the registry for configuration and environment data (‘Query Registry’).
- [T1016] System Network Configuration Discovery – Network configuration is discovered on victim systems (‘System Network Configuration Discovery’).
- [T1016.001] System Network Configuration Discovery: Internet Connection Discovery – Turla checks for internet connectivity (‘Internet Connection Discovery’).
- [T1049] System Network Connections Discovery – Active connections are enumerated (‘System Network Connections Discovery’).
- [T1124] System Time Discovery – The actor checks system time to support operations (‘System Time Discovery’).
- [T1021.002] Remote Services: SMB/Windows Admin Shares – Turla uses SMB/admin shares for lateral movement (‘SMB/Windows Admin Shares’).
- [T1570] Lateral Tool Transfer – Tools are transferred laterally within networks (‘Lateral Tool Transfer’).
- [T1213.006] Data from Information Repositories: Databases – The group collects data from databases (‘Databases’).
- [T1025] Data from Removable Media – Data is collected from removable media (‘Data from Removable Media’).
- [T1560.001] Archive Collected Data: Archive via Utility – Collected data is archived with utilities (‘Archive via Utility’).
- [T1005] Data from Local System – Turla collects data from local systems (‘Data from Local System’).
- [T1071.001] Application Layer Protocol: Web Protocols – C2 traffic uses web protocols (‘Web Protocols’).
- [T1071.003] Application Layer Protocol: Mail Protocols – Mail protocols are used for command and control (‘Mail Protocols’).
- [T1090] Proxy – The actor routes traffic through proxies to hide origin (‘Proxy’).
- [T1090.001] Proxy: Internal Proxy – Internal proxies are used in the C2 chain (‘Internal Proxy’).
- [T1105] Ingress Tool Transfer – Turla downloads or transfers tools into victim environments (‘Ingress Tool Transfer’).
- [T1102] Web Service – The group uses web services for C2 or hosting (‘Web Service’).
- [T1102.002] Web Service: Bidirectional Communication – Web services enable two-way communication (‘Bidirectional Communication’).
- [T1567.002] Exfiltration Over Web Service: Exfiltration to Cloud Storage – Data is exfiltrated via cloud storage services (‘Exfiltration to Cloud Storage’).
Indicators of Compromise
- [Malware names] Turla malware family and campaign tools – Uroburos, STOCKSTAY, Kazuar, Tinyturla-NG, and 9 more items
- [Threat actor aliases] Alternate names for Turla – Group 88, Iron Hunter, Krypton, Sig23, Summit, Secret Blizzard, Snake, Venomous Bear, and Waterbug
- [Target countries] Geographic targeting of Turla activity – Belarus, France, Germany, India, Iran, Iraq, Italy, Kazakhstan, Netherlands, Poland, Romania, Russia, Saudi Arabia, Switzerland, Tajikistan, Ukraine, United States, and Uzbekistan
- [File names] Mentioned malware or backdoor names used in campaigns – STOCKSTAY, Tinyturla-NG, and 2 more items
- [Organizations / sectors] Targeted entities and environments – government organizations, French ministries, Western foreign ministries, defence entities, diplomatic organizations, and technology organizations
Read more: https://www.cyfirma.com/research/apt-profile-turla-group/