Targeting and Compromise of French Entities Using the Turla Intrusion Set
ID: 0b53c357-4b23-4c16-a04f-5c1259efb570
STIX ID: report--0b53c357-4b23-4c16-a04f-5c1259efb570
Threat Score
90/100
Uploaded: 2026-07-29
Published Date: 2026-07-29
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
**Executive summary:** The French inter‑ministerial Cyber Crisis Coordination Center (C4) attributes persistent, high‑sophistication espionage activity against French and European targets to the FSB 16th Center using the Turla intrusion set (active since at least 2004), detailing use of custom malware families (e.g., Uroburos, Kazuar, ComRAT), open‑source tools, exploitation (including zero‑days), complex C2 (satellite, P2P, compromised relays), and confirmed compromises of ministerial email accounts, the French Embassy in Moscow, and other defense, justice, and technology sector victims through 2026.
