Adversary-emulation profile for Turla (G0010 / Venomous Bear / Secret Blizzard / Waterbug / KRYPTON / Snake), Russia's FSB Center 16 cyber-espionage actor.
59
68%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/turla/SKILL.mdTurla (MITRE ATT&CK G0010) is one of the most sophisticated and long-running cyber-espionage groups in existence, attributed to Russia's Federal Security Service (FSB) Center 16, operating since at least 2004. Turla has compromised victims in over 50 countries across government, diplomatic, military, defense, education, research, and pharmaceutical sectors. The group is characterized by extraordinary technical depth — from the Snake/Uroburos kernel rootkit and satellite-based C2 hijacking to steganographic email backdoors and the audacious practice of hijacking other nation-state APTs' infrastructure. Turla's tooling spans Windows, Linux, and macOS, with a malware ecosystem (Snake, Carbon, ComRAT, Kazuar, LightNeuron, Penquin, TinyTurla, Lunar toolset) unmatched in breadth and longevity. The 2023 FBI Operation MEDUSA takedown of the Snake peer-to-peer network — spanning 50+ countries over nearly 20 years — underscored the global scale of Turla's operations.
Out-EncryptedScript.ps1 for encrypted payloads, and custom PowerShell backdoors with RPC-based C2. ESET documented Turla's comprehensive PowerShell-based toolchain in 2019.cmd.exe for command execution.HKLM\...\Run keys; Metasploit shellcode executables saved to Startup folder; Gazer, Kazuar, and Mosquito used Run key persistence.HKCU\...\Winlogon Shell value modifications (Mosquito installer, Gazer).Invoke-ReflectivePEInjection.ps1 for reflective PE injection; Metasploit reflective DLL injection for privilege escalation; IronNetInjector, Kazuar, Uroburos, Carbon, and Gazer used DLL injection.w32time.dll); LunarWeb components mimicked Zabbix agent logs; LightNeuron and Penquin matched legitimate resource names and locations.amsi.dll to bypass Windows AMSI (Antimalware Scan Interface).net use commands.net user, net user /domain; HyperStack, Epic, and Kazuar performed local account enumeration.%TEMP%, desktop, Program Files, and Recent directories; RPC backdoors searched for lPH*.dll pattern; multiple malware families perform targeted file discovery.gpresult to enumerate Group Policy configuration.fsutil fsinfo drives to list connected drives.net localgroup Administrators, net group "Domain Admins" /domain for privilege mapping.tasklist /v and RPC backdoor enumeration of processes by open ports/named pipes; used across Carbon, Epic, Kazuar, Mosquito, LunarWeb, KOPILUWAK, PowerStallion, IronNetInjector.reg query for system enumeration; retrieved stored PowerShell payloads from Registry; checked null-session named pipe configurations.net view, net view /DOMAIN, net group "Domain Computers" /domain, net group "Domain Controllers" /domain, net group "Exchange Servers" /domain for network mapping.systeminfo, set commands; used across Epic, Gazer, Kazuar, LightNeuron, LunarWeb, Penquin, Uroburos.arp -a, nbtstat -n, net config, ipconfig /all, route, NBTscan, and tracert for network reconnaissance.netstat -an, net use, net file, net session; RPC backdoors enumerated TCP connections via GetTcpTable2 API.tasklist /svc for service-to-process mapping.net time command.net accounts, net accounts /domain.net use for lateral connections and PsExec for remote service execution across internal networks.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| Uroburos / Snake | S0022 | Kernel rootkit + P2P C2 network (20-year lifespan) | Custom |
| Carbon | S0335 | Second-stage modular framework | Custom |
| ComRAT (Agent.BTZ lineage) | S0126 | Backdoor with Gmail web-UI C2 | Custom |
| Kazuar | S0265 | Multiplatform espionage backdoor (Windows/Linux) | Custom |
| LightNeuron | S0395 | Exchange Transport Agent backdoor (steganographic C2) | Custom |
| Penquin | S0587 | Linux backdoor (passive, BPF-based activation) | Custom |
| Gazer (WhiteBear) | S0168 | Second-stage Windows backdoor | Custom |
| Mosquito | S0256 | Windows installer/backdoor | Custom |
| Epic | S0091 | First-stage Windows implant (watering hole delivery) | Custom |
| HyperStack | S0537 | RPC-based Windows backdoor | Custom |
| Crutch | S0538 | Document stealer with Dropbox C2 | Custom |
| TinyTurla | S0668 | Minimal fallback backdoor (service-based persistence) | Custom |
| KOPILUWAK | S1075 | JavaScript reconnaissance tool | Custom |
| IronNetInjector | S0581 | .NET/IronPython malware loader | Custom |
| PowerStallion | S0393 | PowerShell backdoor (OneDrive C2) | Custom |
| LunarWeb | S1141 | HTTP backdoor with steganographic C2 | Custom |
| LunarMail | S1142 | Outlook add-in backdoor (email C2) | Custom |
| LunarLoader | S1143 | Reflective loader for Lunar toolset | Custom |
| TwoDash | (no ATT&CK ID) | Backdoor deployed via hijacked Storm-0156 infrastructure | Custom |
| Statuezy | (no ATT&CK ID) | Clipboard monitor deployed via hijacked infrastructure | Custom |
| Mimikatz | S0002 | Credential dumping | Public |
| Empire | S0363 | Post-exploitation framework (PowerShell) | Public |
| Metasploit / Meterpreter | S0261 | Post-exploitation framework | Public |
| PsExec | S0029 | Remote execution | Public (Sysinternals) |
| NBTscan | S0590 | NetBIOS scanner | Public |
| certutil | S0160 | LOLBin (decode, download, certificate install) | Built-in |
| Net / nbtstat / netstat / Reg / Systeminfo / Tasklist | S0039 / S0102 / S0104 / S0075 / S0096 / S0057 | LOLBins | Built-in |
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never deploy kernel rootkits or destructive capabilities outside an explicitly sanctioned, isolated lab environment.
Map Turla's signature plays to Decepticon's own capabilities:
w32time.dll). This serves as a fallback access channel — Turla's signature resilience pattern where minimal implants survive detection of primary tooling..jpg.bfe double extensions. Add a web-service C2 profile (Dropbox/GitHub) for redundancy, emulating Crutch and PowerStallion patterns.Get-TransportAgent); monitor for new or modified DLLs in Exchange transport directories; alert on Exchange process spawning unexpected child processes; inspect email attachments for steganographic anomalies (oversized image/PDF metadata)..jpg.bfe); monitor for programmatic email draft creation.amsi.dll patch attempts; alert on PowerShell profiles modified outside normal administrative processes; detect encoded/encrypted PowerShell scripts using Out-EncryptedScript patterns.RunAsPPL) and Credential Guard; alert on LSASS handle access with PROCESS_VM_READ; monitor for DCSync replication requests from non-DC hosts; detect Kerberos ticket anomalies (golden ticket TGT lifetime, silver ticket service principal mismatches).4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.