Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
espionage
RussiaThreat Actor
Active Threat
Turla
8.4k
IOCs Tracked
628
Intel Reports
Associated IOCs50 total
IP23
91.202.233.214109.73.193.24246.151.182.205162.248.225.16567.219.102.244221.207.101.17515.204.95.2285.101.86.985.101.86.105178.16.54.24888.119.167.14384.21.189.225107.175.148.68137.184.163.27163.181.208.79139.159.203.44195.123.240.2368.152.2.86158.247.194.14438.181.42.16018.118.196.244146.70.41.17435.220.177.232Domain6
wala_rv_2.8.zip2026-10-08High
d-folding-rna-3.9-beta.5.zip2026-10-09High
jerry-tom-server-3.7.zip2026-10-09High
io_github_beyond_solution_3.0.zip2026-10-08High
software-2.2.zip2026-10-09High
terminal-dipdarks-v1.4.zip2026-10-09High
URL20
http://104.168.4.206/dlr.arm2026-10-09High
http://182.127.179.145:57484/bin.sh2026-10-09High
http://104.168.4.206/dlr.mpsl2026-10-09High
http://222.139.36.192:46146/bin.sh2026-10-09High
http://116.139.99.176:37688/bin.sh2026-10-09High
http://123.12.20.207:47682/bin.sh2026-10-09High
http://42.85.120.118:36599/i2026-10-09High
http://83.228.109.209:57061/i2026-10-09High
http://104.64.0.199/hiddenbin/Space.arm62026-10-09High
http://117.131.92.150:54561/bin.sh2026-10-09High
http://66.29.151.122/boatnet.sh42026-10-09High
https://donutclients.st/bnana-client-26.2.jar2026-10-09High
http://115.63.78.29:58952/i2026-10-09High
http://85.95.191.148:57837/i2026-10-09High
http://60.23.238.198:47140/bin.sh2026-10-09High
http://wp.fujeigroup.com:8888/file/img_154255.png2026-10-09High
http://42.57.164.151:60901/i2026-10-09High
http://77.90.14.60/boatnet.m68k2026-10-09High
http://123.9.203.45:54662/bin.sh2026-10-09High
http://61.52.213.183:40640/i2026-10-09High
SHA2561
1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498Related Reports628 total
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Warlock Ransomware Attackers Hit Water and Telecom Operators
SymantecOct 1, 2026
'ChainDrop' worm compromises hundreds of popular npm packages
Datadog Security LabsAug 4, 2026
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Dissecting SnakeKeyLogger Macros
Aziz FarghlyFeb 7, 2024
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
FamousSparrow Takes Flight with New SparroWocky Backdoor
PolySwarmSep 25, 2026
Gamers Get Played: Fake GTA6 Leaks Deliver a Grab Bag of Malware
PolySwarmSep 14, 2026
CLOSEDQUORUM: Malware Puts AI in the C2 Loop
PolySwarmSep 28, 2026
Targeting the Systems Behind the Mission: OT Threats to US Critical Infrastructure and Military Operations
PolySwarmOct 5, 2026
BraZetsu: AI-Enhanced Reconnaissance Fuels Exilware’s Access Marketplace
PolySwarmSep 11, 2026
Lunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealer
PolySwarmOct 2, 2026
China and the Cyber Arms Race for AI Supremacy
PolySwarmSep 21, 2026
The Job Offer Has Claws: Mirage Kitten Deploys NodeRabbit and PollCat
PolySwarmSep 8, 2026
BlueMoon Exploit Kit Rapidly Targets Key Verticals Across Multiple Espionage Campaigns
PolySwarmSep 21, 2026
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
How Huntress Detects and Responds to a ClickFix Attack
HuntressOct 5, 2026
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google Threat Intelligence (GTIG / Mandiant)Jun 25, 2026
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service
Proofpoint Threat InsightJul 20, 2026
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Threat Profile
Motivationespionage
Origin
Russia
Last seenOct 2026
IOCs tracked8,397