Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0010
MITRE ATT&CK Group

Turla (G0010)

IRON HUNTERGroup 88WaterbugWhiteBearSnakeKryptonVenomous BearSecret BlizzardBELUGASTURGEON
ShareXLinkedInRedditHN

[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. [Turla](https://attack.mitre.org/groups/G0010) is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as [Uroburos](https://attack.mitre.org/software/S0022).(Citation: Kaspersky Turla)(Citation: ESET Gazer Aug 2017)(Citation: CrowdStrike VENOMOUS BEAR)(Citation: ESET Turla Mosquito Jan 2018)(Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023)

▪Techniques used (68)

T1584.006Web ServicesT1112Modify RegistryT1069.001Local GroupsT1140Deobfuscate/Decode Files or InformationT1588.002ToolT1059.007JavaScriptT1134.002Create Process with TokenT1059.005Visual BasicT1546.013PowerShell ProfileT1583.006Web ServicesT1055.001Dynamic-link Library InjectionT1105Ingress Tool TransferT1555.004Windows Credential ManagerT1090ProxyT1068Exploitation for Privilege EscalationT1615Group Policy DiscoveryT1049System Network Connections DiscoveryT1106Native APIT1071.003Mail ProtocolsT1021.002SMB/Windows Admin SharesT1547.001Registry Run Keys / Startup FolderT1005Data from Local SystemT1012Query RegistryT1007System Service DiscoveryT1110Brute ForceT1570Lateral Tool TransferT1189Drive-by CompromiseT1584.004ServerT1087.002Domain AccountT1685Disable or Modify ToolsT1564.012File/Path ExclusionsT1120Peripheral Device DiscoveryT1567.002Exfiltration to Cloud StorageT1102.002Bidirectional CommunicationT1071.001Web ProtocolsT1124System Time DiscoveryT1087.001Local AccountT1204.001Malicious LinkT1090.001Internal ProxyT1546.003Windows Management Instrumentation Event SubscriptionT1560.001Archive via UtilityT1059.003Windows Command ShellT1057Process DiscoveryT1016System Network Configuration DiscoveryT1587.001MalwareT1025Data from Removable MediaT1518.001Security Software DiscoveryT1059.001PowerShellT1027.010Command ObfuscationT1059.006PythonT1213.006DatabasesT1018Remote System DiscoveryT1588.001MalwareT1069.002Domain GroupsT1027.011Fileless StorageT1547.004Winlogon Helper DLLT1553.006Code Signing Policy ModificationT1566.002Spearphishing LinkT1016.001Internet Connection DiscoveryT1102Web ServiceT1082System Information DiscoveryT1584.003Virtual Private ServerT1036.005Match Legitimate Resource Name or LocationT1055Process InjectionT1078.003Local AccountsT1201Password Policy DiscoveryT1083File and Directory DiscoveryT1027.005Indicator Removal from Tools

▪Software used (30)

S0029PsExectoolS0102nbtstattoolS0126ComRATmalwareS0104netstattoolS0160certutiltoolS0363EmpiretoolS0256MosquitomalwareS1075KOPILUWAKmalwareS0581IronNetInjectortoolS1141LunarWebmalwareS0099ArptoolS0538CrutchmalwareS0022UroburosmalwareS0393PowerStallionmalwareS0168GazermalwareS0265KazuarmalwareS0096SysteminfotoolS0395LightNeuronmalwareS0335CarbonmalwareS0002MimikatztoolS0057TasklisttoolS1142LunarMailmalwareS0039NettoolS0075RegtoolS0537HyperStackmalwareS0091EpicmalwareS0590NBTscantoolS0668TinyTurlamalwareS0587PenquinmalwareS1143LunarLoadermalware
G0010on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.