logo

Targeting and Compromise of French Entities Using the Turla Intrusion Set

ID: 0b53c357-4b23-4c16-a04f-5c1259efb570

STIX ID: report--0b53c357-4b23-4c16-a04f-5c1259efb570

Threat Score

90/100

Uploaded: 2026-07-29

Published Date: 2026-07-29

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
**Executive summary:** The French inter‑ministerial Cyber Crisis Coordination Center (C4) attributes persistent, high‑sophistication espionage activity against French and European targets to the FSB 16th Center using the Turla intrusion set (active since at least 2004), detailing use of custom malware families (e.g., Uroburos, Kazuar, ComRAT), open‑source tools, exploitation (including zero‑days), complex C2 (satellite, P2P, compromised relays), and confirmed compromises of ministerial email accounts, the French Embassy in Moscow, and other defense, justice, and technology sector victims through 2026.