Netskope Threat Labs

Turla

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Turla is a threat group associated with Russian state sponsored espionage that has conducted sophisticated campaigns against diplomatic and military targets for over two decades. Its tooling spans satellite based command and control, rootkits, and custom backdoors, and its operators favor long dwells and creative persistence over quick data grabs. The group's operations and code reuse have shaped how defenders understand state sponsored espionage tradecraft.

First seen
February 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Backdoor.Turla
Document-Word.Dropper.Turla
Dump:Generic.Backdoor.Turla.C.31AF83D1
Gen:Variant.Backdoor.Turla.12
Gen:Variant.Backdoor.Turla.15
Gen:Variant.Backdoor.Turla.16
Gen:Variant.Trojan.Linux.Turla.1
Gen:Variant.Turla.10
Gen:Variant.Turla.19
Gen:Variant.Turla.24