Skip to main content
All Threat Actors
🇷🇺

Turla

Also known as: Snake, Venomous Bear, KRYPTON, Secret Blizzard

Russian FSB. Sophisticated espionage. Snake malware. Active since 1990s.

Origin: Russia
Targets
governmentdiplomaticmilitary

Associated Intelligence

Turla Upgrades Kazuar to P2P Botnet

Russia-linked APT group Turla has upgraded its Kazuar malware to a modular peer-to-peer botnet, allowing for stealthy and persistent access to compromised systems. This upgrade enables long-term

16/5/2026High

Russian Hackers Expand Kazuar Backdoor

A Russian hacker group has developed the Kazuar backdoor into a modular peer-to-peer botnet, potentially affecting organizations with compromised systems. The botnet is designed for long-term persistence, stealth, and data collection, making it a significant threat. Users with potentially vulnerable systems should review their security measures and update their defenses.

16/5/2026High

Turla Upgrades Kazuar to P2P Botnet

The Russian state-sponsored hacking group Turla has upgraded its Kazuar backdoor to a modular peer-to-peer (P2P) botnet, enabling stealthy and persistent access to compromised hosts. This development affects organizations with potentially vulnerable systems. Users should exercise caution and monitor for suspicious activity.

15/5/2026High

Kazuar Nation-State Botnet

A sophisticated malware family, Kazuar, attributed to the Russian state actor Secret Blizzard, has been evolving to support espionage-focused operations. This malware has expanded into a highly modular peer-to-peer botnet ecosystem, enabling persistent and covert access to target environments. Organizations should be aware of this threat and take measures to protect their networks.

14/5/2026High