Cyber Resilience

Threat actor · all actors

TurlaG0010 state

🇷🇺 RU · FSB · Center 16

aka Turla, IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON, WRAITH, Uroburos, Pfinet, TAG_0530, Hippo Team, Pacifier APT, Popeye, SIG23, MAKERSMARK, ATK13, G0010, ITG12, Blue Python, SUMMIT, UNC4210, UAC-0144, UAC-0024, UAC-0003, TURLA RELIC, White Bear, Skipper Turla

Last updated: 2026-08-20

0attributed CVEs
92ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

As a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting APT activity that we called WhiteBear. Much of the contents of that report are reproduced here. WhiteBear is a parallel project or second stage of the Skipper Turla cluster of activity documented in another private intelligence report “Skipper Turla – the White Atlas framework” from mid-2016. Like previous Turla activity, WhiteBear leverages compromised websites and hijacked satellite connections for command and control (C2) infrastructure. As a matter of fact, WhiteBear infrastructure has overlap with other Turla campaigns, like those deploying Kopiluwak, as documented in “KopiLuwak – A New JavaScript Payload from Turla” in December 2016. WhiteBear infected systems maintained a dropper (which was typically signed) as well as a complex malicious platform which was always preceded by WhiteAtlas module deployment attempts. However, despite the similarities to previous Turla campaigns, we believe that WhiteBear is a distinct project with a separate focus. We note that this observation of delineated target focus, tooling, and project context is an interesting one that also can be repeated across broadly labeled Turla and Sofacy activity. From February to September 2016, WhiteBear activity was narrowly focused on embassies and consular operations around the world. All of these early WhiteBear targets were related to embassies and diplomatic/foreign affair organizations. Continued WhiteBear activity later shifted to include defense-related organizations into June 2017. When compared to WhiteAtlas infections, WhiteBear deployments are relatively rare and represent a departure from the broader Skipper Turla target set. Additionally, a comparison of the WhiteAtlas framework to WhiteBear components indicates that the malware is the product of separate development efforts. WhiteBear infections appear to be preceded by a condensed spearphishi

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0010

Microsoftweather-system names

Secret Blizzard

CrowdStrikenation-animal names

Venomous BearWhite Bear

MandiantUNC uncategorised cluster

UNC4210

Secureworkscolour-metal names

IRON HUNTER

CERT-UAUAC cluster id

UAC-0144UAC-0024UAC-0003

Unclassifiedno scheme matched

TurlaGroup 88WaterbugWhiteBearSnakeKryptonBELUGASTURGEONWRAITHUroburosPfinetTAG_0530Hippo TeamPacifier APTPopeyeSIG23MAKERSMARKATK13ITG12Blue PythonSUMMITTURLA RELICSkipper Turla

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 92 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-451 / 9255%
CM-645 / 9249%
CM-239 / 9242%
SI-338 / 9241%
AC-633 / 9236%
CM-732 / 9235%
CA-731 / 9234%
AC-330 / 9233%
AC-227 / 9229%
SC-723 / 9225%
SI-720 / 9222%
AC-419 / 9221%
SI-217 / 9218%
CM-516 / 9217%
SI-1015 / 9216%

Co-occurring actors

None.

Similar actors