Executive Summary
Turla, a Russia-aligned APT linked to the FSB, has maintained a high-tempo cyber-espionage operation since at least 2004. The group's primary focus is long-term intelligence collection against government, defense, and research organizations, with a recent heavy concentration on Ukrainian targets. Turla is known for its high level of operational stealth, frequently hijacking the C2 infrastructure of other threat actors, such as OilRig and Storm-0156, to mask its activities and expand its reach.
The group utilizes a sophisticated custom toolset, most notably the STOCKSTAY and Kazuar backdoors, which share a common obfuscation ecosystem (K1MORPHER). Their attack chain often includes specialized delivery mechanisms like malicious RDP configuration files and the exploitation of path-traversal vulnerabilities. Turla avoids traditional C2 attribution by routing traffic through legitimate serverless platforms and cloud services, while implementing environmental keying to ensure payloads only execute on intended victim machines.
Turla represents a persistent, high-tier threat capable of compromising supply chains and ISPs to conduct Adversary-in-the-Middle (AiTM) attacks. Their ability to adapt and integrate their tools with other actors' infrastructure makes them exceptionally difficult to track and attribute, requiring a defense-in-depth approach focused on behavioral detection and rigorous monitoring of cloud service abuse.
Key Details
Threat Name
Turla APT
Affects
WinRAR, Oracle PeopleSoft
Adversary
Turla Other Adversaries and Aliases: OilRig; Storm-0156; Gamaredon
MITRE Techniques
Malware/Tools
STOCKSTAY, Kazuar, ApolloShadow, TinyTurla, LunarWeb, LunarMail, Chisel, Agent.BTZ, ComRAT, DIAMONDBACK
