Turla RAT is a sophisticated remote access trojan (RAT) family employed by the Russian-speaking advanced persistent threat group tracked as Turla (MITRE ATT&CK ID: G0010). First identified by Kaspersky in 2014 as an evolution of the earlier Uroburos malware, it is used primarily for cyberespionage against government, diplomatic, military, and research organizations. The group is assessed to be state-sponsored and has been active since at least 2008.
Turla RAT implants are highly modular, using a custom encrypted communication protocol over both TCP and UDP for command-and-control (C2). Propagation occurs via spearphishing with malicious attachments, exploitation of internet-facing services, and lateral movement using legitimate administrative tools. Persistence is achieved through registry run keys, scheduled tasks, and service installations. Evasion techniques include rootkit components that hide registry keys and file system artifacts (e.g., the Uroburos driver), as well as encrypted payloads and use of legitimate cloud services like Dropbox for C2 relay (observed in the Carbon weaponized version). A notable variant, ComRAT v4, uses HTTP with custom headers and leverages compromised mail servers for C2 fallback, as documented by ESET in 2020.
Turla RAT first appeared in the mid-2000s but gained notoriety during campaigns targeting Iranian nuclear program networks (2015, Kaspersky report) and European foreign ministries (2017, ESET). In 2019, a version exploiting CVE-2019-2215 (Android kernel vulnerability) was used against Ukrainian soldiers. The group also compromised the European Parliament and the German Foreign Office (2021, BSI warning). No law enforcement takedowns have been publicly reported.
Known file hashes include SHA256 2b3a5d6e7f8c9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4 (Snake dropper, published by US-CERT). Behavioral signatures include outbound connections to unusual ports (e.g., TCP 443 in combination with UDP 53), registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence, and creation of mutex names like GlobalWINSAPP. Network IOCs include user-agent strings such as Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 used by ComRAT HTTP beacons.
Damage includes complete compromise of targeted systems, long-term stealthy data exfiltration of sensitive documents, internal emails, and cryptographic keys. Turla has impacted hundreds of governmental and military networks globally, with financial losses estimated in the hundreds of millions for cleanup and incident response. Sectors targeted include defense, energy, and diplomatic corps, as noted in reports from the UK NCSC and US CISA.
Recommended defenses include applying patches for CVEs used by Turla (e.g., CVE-2019-2215 for Android), enforcing application whitelisting, implementing network segmentation, and monitoring for anomalous outbound connections to cloud services. SIEM rules based on MITRE ATT&CK techniques T1059 (Command and Scripting Interpreter) and T1572 (Protocol Tunneling) can detect Turla activity, along with YARA rules published by ESET (e.g., Win32/Turla.C).
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.