Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Turla, Waterbug, Venomous Bear, Group 88, SIG2, SIG15, SIG23, Iron Hunter, CTG-8875, Pacifier APT, ATK 13, ITG12, Makersmark, Krypton, Belugasturgeon, Popeye, Wraith, TAG-0530, UNC4210, SUMMIT, Secret Blizzard, Pensive Ursa, Blue Python, G0010, Snake, VENOMOUS Bear, WRAITH, Uroburos, Pfinet, TAG_0530, KRYPTON, Hippo Team, IRON HUNTER, MAKERSMARK, ATK13, UAC-0144, UAC-0024, UAC-0003, WhiteBear, BELUGASTURGEON
Turla is a Russian-based threat group that has infected victims in over 45 countries, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies since 2004. Heightened activity was seen in mid-2015. Turla is known for conducting watering hole and spear-phishing campaigns and leveraging in-house tools and malware. Turla’s espionage platform is mainly used against Windows machines, but has also been seen used against macOS and Linux machines. Turla has been known to also infiltrate malicious infrastructure from other APT groups such as Transparent Tribe, APT 36 in 2022.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database