More about the Turla group, its tactics, techniques, procedures and tools
Usage of satellite internet connection to hide command and control servers
Russian language artefacts
A Russian-speaking APT active since at least 1997 when it was suspected of being responsible for the Moonlight Maze operation. The group has been implicated in many high profile incidents, including the 2008 attack against the US Central Command. This actor leverages a wide variety of malware and is capable of compromising web servers, deploying zero-day exploits, effectively spear-phishing targets, developing network worms, and staying unnoticed for long periods. Their main targets are located in Central Asia and CIS countries, but they’ve also attacked NATO, global embassies, and government agencies in the Middle East.