logo svg
logo

September 7, 2026

Updated: September 7, 2026

Turla (Secret Blizzard): FSB Spies Who Hijack Hackers

Twenty years of quiet FSB collection, and a habit of stealing other intrusion sets' infrastructure so the blame lands on someone else.

Abdalla Mohamed

Featured Image

Updated: September 2026

The quick answer

Turla is one of the world's oldest and most sophisticated cyber espionage groups, attributed to Center 16 of Russia's Federal Security Service (FSB) and tracked in MITRE ATT&CK as G0010. Also called Secret Blizzard, Snake, Uroburos, Waterbug, and Venomous Bear, it has operated since at least 2004, with roots reaching back to the 1990s. Turla targets governments, embassies, and militaries in more than 50 countries for long-term intelligence. Its signature move is stealing and hijacking the infrastructure of other hacker groups to spy through them and shift the blame.

What is Turla?

What is Turla?

Turla is a Russian state-sponsored espionage group run by the FSB, Russia's principal security and intelligence service, specifically a unit within FSB Center 16 based in Ryazan and Moscow. Unlike Russia's military-intelligence groups such as APT28 (Fancy Bear) and the destructive Sandworm, Turla is a pure espionage outfit. It wants to stay hidden and steal secrets for years, not cause disruption.

Its objective is long-term strategic intelligence gathering rather than financial gain or sabotage. According to a 2023 joint advisory led by CISA and the FBI, Turla's Snake malware, the FSB's premier espionage tool, was found in more than 50 countries, targeting government networks, research facilities, and journalists, and used to exfiltrate diplomatic communications from a NATO member. Turla is a benchmark actor in the state-sponsored APT landscape and a regular entry on any list of the world's most advanced hacking groups.

What makes Turla remarkable is patience and craft. It builds stealthy rootkits, communicates over channels designed to defeat detection, and, most distinctively, parasitizes other threat actors rather than always exposing its own tools.

The many names of Turla

Because Turla has been studied for two decades by many vendors and governments, it carries a long list of names for the same FSB unit and its toolset.

AliasAssigned by
Turla / Turla TeamCommunity (MITRE G0010)
Secret BlizzardMicrosoft (current)
Snake / Uroburosafter its flagship malware
WaterbugSymantec
Venomous BearCrowdStrike
Krypton / WhiteBearearly reporting
Iron HunterSecureworks
Pensive UrsaPalo Alto Unit 42
UNC4210Mandiant (Andromeda cluster)
SUMMITGoogle GTIG
UAC-0194CERT-UA

The anchor term is Turla, but a CISA report on Snake, a Microsoft report on Secret Blizzard, and a Symantec report on Waterbug all describe the same group.

Turla's signature move: hijacking other hackers' infrastructure

The reason Turla gets its own profile is a tactic almost no other group uses at scale: it takes over the command-and-control (C2) infrastructure and tools of other hacker groups and spies through them. This does two things at once. It gives Turla ready-made footholds inside networks someone else already breached, and it launders attribution, so incident responders who find the intrusion often blame the original actor. Researchers have documented at least four major cases, and Microsoft assesses Turla has hijacked at least six state-sponsored and criminal groups since 2017.

The strategic payoff is deniability. As Lumen's Black Lotus Labs put it, exploiting another actor's servers lets Turla collect already-stolen data without exposing its own tools and shifts suspicion onto someone else, delaying or defeating attribution.

Major Turla operations and history

Turla's timeline spans nearly the entire history of nation-state hacking.

Moonlight Maze and the deep roots (1996 to 2008)

Researchers link Turla's lineage to Moonlight Maze, one of the first known state cyber-espionage campaigns against the United States in the late 1990s. In 2008, the Agent.BTZ worm jumped the air gap into a classified US Department of Defense network via infected USB drives, an incident that helped spur the creation of US Cyber Command and was later tied to Turla's toolset.

Snake and Uroburos (2004 onward)

Turla's flagship is Snake, developed as Uroburos beginning around 2003 to 2004. It is a kernel-level rootkit that builds a covert peer-to-peer network of infected machines to relay traffic, using custom encrypted protocols to hide from detection. The FSB re-engineered it repeatedly across nearly 20 years rather than abandoning it after public disclosures.

Satellite command and control (2015)

Turla pioneered hijacking satellite internet downlinks for C2, spoofing the IP addresses of legitimate satellite subscribers so its stolen data appeared to vanish into space, an early example of its infrastructure-abuse creativity.

Operation MEDUSA (2023)

In May 2023, the FBI and international partners ran Operation MEDUSA, using a tool called PERSEUS to exploit a weakness in Snake's encryption and command infected machines worldwide to disable the malware, a rare and significant disruption of an active FSB platform.

The freeloader era (2022 to 2026)

Turla's recent operations lean heavily on the infrastructure-hijacking tactic above, from Andromeda in Ukraine to the Storm-0156 and Amadey campaigns detailed by Microsoft and Lumen in late 2024. In parallel it has kept building fresh custom tooling, including the TinyTurla-NG backdoor used against Polish NGOs and, most recently, the STOCKSTAY implant.

STOCKSTAY and the 2026 toolkit

In June 2026, Google's Threat Intelligence Group detailed STOCKSTAY, a modular .NET backdoor Turla (tracked by Google as SUMMIT and by Ukraine's CERT-UA as UAC-0194) has developed since at least December 2022. STOCKSTAY talks to its command server over an encrypted WebSocket channel and disguises itself as a stock-market or cryptocurrency trading app, with later variants posing as PDF viewers and calculator utilities. It shares significant code with Turla's earlier Kazuar toolkit, and Google observed it hitting Ukrainian government and military targets as well as entities tied to Italian foreign policy, with early samples surfacing in Italy, the Netherlands, Poland, and Germany.

Two details capture how Turla operates in 2026. First, it leans on legitimate platforms to hide: it has hosted STOCKSTAY command servers on services like GitHub and the Render cloud platform, and because the malware encrypts its own messages end to end, the hosting provider cannot inspect the traffic passing through its infrastructure. Second, the group shows a consistent taste for academic and diplomatic cover, compromising a Ukrainian university email account and a diplomatic-education platform to send phishing, and even naming an installer product "DiplomacyEduAI." Separately, Turla has deployed scripts designed to intercept secure messages from Signal Messenger users, extending its espionage reach into encrypted chat.

Turla tactics, malware, and MITRE ATT&CK techniques

Turla tactics, malware, and MITRE ATT&CK techniques

Turla's MITRE ATT&CK group ID is G0010. Searching for Turla MITRE surfaces the full catalog; the techniques below define its stealth-first, parasitic playbook.

TechniqueATT&CK IDHow Turla uses it
Compromise infrastructureT1584Hijacking other actors' C2 servers and domains
Compromise infrastructure: botnetT1584.005Co-opting Andromeda and Amadey botnets
Drive-by compromiseT1189Watering-hole attacks on compromised websites
PhishingT1566Spear-phishing embassies and government targets
RootkitT1014The Snake kernel rootkit and P2P relay network
Web service C2T1102Hiding traffic in GitHub, Cloudflare, Render, and email services
Application layer protocolT1071.001Custom encrypted protocols and WebSocket channels
Adversary-in-the-middleT1557Intercepting Signal Messenger communications
Valid accountsT1078Stolen credentials harvested from hijacked infrastructure

Its malware family is one of the deepest in espionage: Snake and Uroburos, Carbon (from the Snake codebase), ComRAT (the Agent.BTZ successor), Kazuar and KazuarV2, Tavdig, Mosquito, Gazer, the Exchange backdoor LightNeuron, Crutch, TinyTurla and TinyTurla-NG, QUIETCANARY, the WebSocket backdoor STOCKSTAY, and the TwoDash and Statuezy tools used in its hijacking campaigns. It also weaponizes tools it steals from other actors, like Iran's Neuron and Nautilus.

A Turla infrastructure-hijack attack, step by step

The Storm-0156 campaign shows how Turla spies through another group.

  1. Find a foothold someone else built. Turla identified the C2 servers of the Pakistani group Storm-0156, which had already breached Afghan and Indian government networks.
  2. Compromise the C2. It quietly took control of those servers, gaining the access and stolen data the Pakistani operators had accumulated.
  3. Spy through the original actor's victims. Using the pre-existing footholds, Turla deployed its own TwoDash and Statuezy malware into Afghan government networks without breaching them directly.
  4. Move up the chain. It pivoted from the C2 servers into the Pakistani operators' own workstations, stealing their credentials, tooling, and previously exfiltrated data.
  5. Harvest and hide. Turla selectively used the stolen CrimsonRAT infrastructure to reach high-value Indian targets, all while any investigation would likely blame Pakistan, not Russia.

The entire operation is a form of living off the land applied to other hackers, using their access and their tools so Turla's own footprint stays minimal.

How to defend against Turla

Turla wins through stealth, patience, and misdirection, so defenses should focus on deep visibility, covert-channel detection, and not taking attribution at face value. Validate each control with real testing rather than assuming it holds.

Hunt for covert C2 and stealthy persistence

Turla's Snake hides in kernel space and relays traffic through custom encrypted protocols and legitimate services like GitHub, Cloudflare, and Render, so signature-based tools miss it, and because newer backdoors such as STOCKSTAY encrypt their own traffic end to end, even the hosting providers cannot see it. Invest in behavioral detection and network anomaly hunting, follow the technical indicators in the CISA and FBI Snake advisory, and inspect outbound traffic to cloud and web services that could mask C2. Reducing your attack surface limits the footholds available in the first place.

Watch the doors Turla borrows

Because Turla exploits watering-hole compromises, phishing, and other actors' malware, harden the basics: patch internet-facing systems quickly with disciplined patch management, enforce phishing-resistant multifactor authentication, and practice strict USB and removable-media hygiene given Turla's history of air-gap jumps. Treat any existing infection, even one that looks like commodity crime or another APT, as a possible Turla foothold and investigate fully.

Do not trust attribution blindly

Turla's whole strategy is to hide behind others, so a finding of malware attributed to one group does not rule out a second actor riding on top. Share and consume high-quality threat intelligence, including through standards like STIX and TAXII, and correlate across sources before concluding who is really in your network.

Test and rehearse

Assumptions about visibility, segmentation, and detection are exactly what a patient actor like Turla exploits. Regular penetration testing and red team exercises reveal whether a quiet, long-dwell intruder would actually be caught, and a well-drilled incident response plan built for stealthy espionage shortens the years Turla likes to spend undetected.

Why this matters for security teams

Turla dismantles the assumption that one intrusion means one adversary. In a world where groups steal each other's tools and ride each other's infrastructure, the malware you find may not belong to the actor who is actually reading your data. That has direct consequences for how you investigate, attribute, and respond to any incident, not just a suspected FSB operation.

Even organizations that will never be an FSB priority should absorb the lesson: shared and stolen tooling is now normal across the threat landscape, from nation-states to criminals, and it touches nearly every industry attackers target. Building deep visibility and treating attribution as a hypothesis rather than a conclusion is the defense Turla keeps teaching, and it applies far beyond one Russian spy agency, including against Russia's other services like the SVR's APT29.

FAQ

What is Turla?

Turla is a Russian state-sponsored cyber espionage group attributed to Center 16 of the FSB, Russia's Federal Security Service, and tracked as MITRE ATT&CK G0010. Active since at least 2004, it is also known as Secret Blizzard, Snake, Waterbug, and Venomous Bear, and it specializes in long-term intelligence collection.

What is Snake malware?

Snake, also called Uroburos, is Turla's flagship espionage tool, a sophisticated kernel-level rootkit that forms a covert peer-to-peer network to relay traffic and hide command and control. US and allied agencies called it the FSB's premier espionage implant and disrupted it in 2023 through Operation MEDUSA.

What is STOCKSTAY?

STOCKSTAY is a modular .NET backdoor Turla has developed since December 2022, detailed by Google in 2026. It communicates over encrypted WebSocket connections, disguises itself as stock-market, cryptocurrency, or utility apps, shares code with Turla's Kazuar toolkit, and has targeted Ukrainian government and military systems and Italian foreign-policy interests.

What is Turla's MITRE ATT&CK ID?

Turla's MITRE ATT&CK group identifier is G0010. The catalog maps it to techniques including compromise infrastructure (T1584), drive-by compromise via watering holes (T1189), rootkits (T1014), and web-service command and control (T1102) using platforms like GitHub and Cloudflare.

Is Turla the same as Secret Blizzard?

Yes. Secret Blizzard is Microsoft's current name for Turla. The group is also tracked as Snake, Waterbug, Venomous Bear, and Uroburos. All of these labels refer to the same FSB Center 16 espionage unit.

Why does Turla hijack other hackers' infrastructure?

Turla takes over other groups' command-and-control servers and tools to gain ready-made access to networks they already breached, and to launder attribution. If investigators find the intrusion, they often blame the original actor, letting Turla spy while shifting suspicion elsewhere.

What is Turla known for?

Turla is known for the Snake rootkit, the 2008 Agent.BTZ breach of a classified US military network, hijacking satellite communications for stealthy C2, and repeatedly commandeering the infrastructure of Iranian, Pakistani, and cybercriminal groups to spy through them.

Facing a patient, stealth-first adversary like Turla? DeepStrike's penetration testing and red team services stress-test your detection, segmentation, and covert-channel visibility the way a nation-state espionage group would. Explore our penetration testing services to find the gaps before an adversary does.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us