Secret Blizzard
actor · actor:secretblizzard single-source
Russian FSB Centre 16 APT (Microsoft: Secret Blizzard; historically Turla); 2026 coverage includes Microsoft Threat Intelligence's Kazuar P2P botnet anatomy (2026-05-14) and the STOCKSTAY diplomatic-espionage backdoor of Kazuar lineage.
Aliases: Turla, FSB Centre 16, TURLA RELIC
Action items (1)
Do-now tasks recorded on the entries about Secret Blizzard, newest first. Check the date before acting on an older one.
- Disable Cisco Smart Install (2026-07-13CVE-2018-0171
no vstack) and confirm CVE-2018-0171 is remediated on every internet-facing IOS/IOS XE device, and alert on inbound SNMP Set-Requests carrying the config-copy OIDs named in the advisory (1.3.6.1.4.1.9.9.96.1.1 Cisco Config Copy; 1.3.6.1.4.1.9.9.96.1.1.1.1.5 Config Copy Server Address); both are in-use FSB Centre 16 access and config-exfiltration vectors.
Defender insights
What each entry about Secret Blizzard tells a defender to do, newest first.
Detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
collaborates with
- GamaredonESET documents Gamaredon-Turla operational collaboration
documented in
- ESET Gamaredon 2025 annual paperthe ESET Gamaredon paper documents the Turla collaboration
related to
- Static TundraSibling clusters under the same FSB 16th Centre parent unit, the 16th Centre 'controls groups like Turla' per heise EU-sanctions reporting (2026-07-13) and the morning Static Tundra advisory; COMCYBER's page addresses only the Turla mode
attributed activity
- France/EU formal attribution of Turla (FSB Centre 16) espionage against FranceFrance (ANSSI/C4) and the EU High Representative formally attributed the Turla intrusion set to the FSB 16th Centre on 2026-07-13
- Turla STOCKSTAY campaign
Story timeline
Every entry that names Secret Blizzard, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-07-13AIVD/MIVD: Russia-linked actors hijack default-credential IP cameras along NATO military-supply routes to monitor Ukraine-bound shipments
- 2026-07-13FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions
- 2026-06-27Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection
- 2026-06-26ESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)
Hunting pivots
ATT&CK techniques (29 across 13 tactics)
29 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning: Scanning IP Blocks · Active Scanning: Vulnerability Scanning
- Resource DevelopmentAcquire Infrastructure: Virtual Private Server · Compromise Infrastructure: Server · Compromise Infrastructure: Network Devices · Obtain Capabilities: Exploits
- Initial AccessValid Accounts · Drive-by Compromise · Exploit Public-Facing Application · Phishing · Phishing: Spearphishing Attachment
- ExecutionCommand and Scripting Interpreter · User Execution: Malicious File
- PersistenceValid Accounts · Boot or Logon Autostart Execution · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationExploitation for Privilege Escalation · Valid Accounts · Boot or Logon Autostart Execution · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information · Valid Accounts · Execution Guardrails
- Defense ImpairmentModify System Image: Patch System Image
- Credential AccessOS Credential Dumping
- CollectionData from Local System · Data from Configuration Repository: SNMP (MIB Dump) · Data from Configuration Repository: Network Device Configuration Dump
- Command and ControlApplication Layer Protocol · Application Layer Protocol: Web Protocols · Proxy
- ExfiltrationExfiltration Over C2 Channel · Exfiltration Over Alternative Protocol
- ImpactData Destruction
Reconnaissance TA0043
T1595.001Active Scanning: Scanning IP Blocks×1
Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1595.002Active Scanning: Vulnerability Scanning×1
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Resource Development TA0042
T1583.003Acquire Infrastructure: Virtual Private Server×1
Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. By utilizing a VPS, adversaries can make it difficult to physically tie back operations to them. The use of cloud infrastructure can also make it easier for adversaries to rapidly provision, modify, and shut down their infrastructure.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1584.004Compromise Infrastructure: Server×1
Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1584.008Compromise Infrastructure: Network Devices×1
Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1588.005Obtain Capabilities: Exploits×1
Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1189Drive-by Compromise×1
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1566Phishing×2
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1566.001Phishing: Spearphishing Attachment×1
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1547Boot or Logon Autostart Execution×1
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1547Boot or Logon Autostart Execution×1
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1480Execution Guardrails×1
Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
Defense Impairment TA0112
T1601.001Modify System Image: Patch System Image×1
Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a monolithic architecture, where the entire operating system and most of the functionality of the device is contained within a single file. Adversaries may change this file in storage, to be loaded in a future boot, or in memory during runtime.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Credential Access TA0006
T1003OS Credential Dumping×1
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Collection TA0009
T1005Data from Local System×1
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1602.001Data from Configuration Repository: SNMP (MIB Dump)×1
Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1602.002Data from Configuration Repository: Network Device Configuration Dump×1
Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Adversaries can inspect the configuration files to reveal information about the target network and its layout, the network device and its software, or identifying legitimate accounts and credentials for later use.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×2
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Exfiltration TA0010
T1041Exfiltration Over C2 Channel×1
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗
T1048Exfiltration Over Alternative Protocol×1
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Impact TA0040
T1485Data Destruction×1
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Entries about Secret Blizzard (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cisco IOS×1
- Cisco IOS XE×1
- Cisco IOS/IOS XE Smart Install pre-auth RCE, actively exploited by FSB Centre 16 / Static Tundra×1
- France/EU formal attribution of Turla (FSB Centre 16) espionage against France×1
- Poland energy-sector destructive attack (29 December 2025)×1
- Russian hijacking of IP cameras along NATO military-supply routes (2026-07)×1
- Sandworm×1
- Static Tundra×1
Where this entity is cited
Source distribution
- attack.mitre.org5 (22%)
- bleepingcomputer.com2 (9%)
- nltimes.nl2 (9%)
- blog.talosintelligence.com1 (4%)
- cert.pl1 (4%)
- cert.ssi.gouv.fr1 (4%)
- cloud.google.com1 (4%)
- cyber.gouv.fr1 (4%)
- other9 (39%)
All cited sources (23)
- attack.mitre.org`T1041`https://attack.mitre.org/techniques/T1041/
- attack.mitre.org`T1071.001`https://attack.mitre.org/techniques/T1071/001/
- attack.mitre.org`T1480`https://attack.mitre.org/techniques/T1480/
- attack.mitre.org`T1547.001`https://attack.mitre.org/techniques/T1547/001/
- attack.mitre.org`T1566.001`/`.002`https://attack.mitre.org/techniques/T1566/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/static-tundra/
- cert.plCERT Polskahttps://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/
- cert.ssi.gouv.frCERT-FR (ANSSI)https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/
- cloud.google.comGoogle Cloud / GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering
- cyber.gouv.frANSSI (cyber.gouv.fr)https://cyber.gouv.fr/actualites/ciblage-et-compromission-dentites-francaises-par-le-fsb/
- defense.gouv.frMinistère des Armées / COMCYBERhttps://www.defense.gouv.fr/comcyber/actualites/ciblage-compromission-dentites-francaises-au-moyen-du-mode-du-mode-operatoire-dattaque-turla
- gov.ukUK Government (FCDO)https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions
- heise.deheise onlinehttps://www.heise.de/en/news/EU-sanctions-Russia-for-serious-cyberattacks-and-sabotage-11363418.html
- media.defense.govNSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF
- ncsc.gov.ukNCSC-UKhttps://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting
- nltimes.nlNL Times (ANP)https://nltimes.nl/2026/07/11/dutch-spy-agencies-russia-hacked-cameras-spy-military-routes
- nltimes.nlNL Times (ANP)https://nltimes.nl/2026/07/13/netherlands-summons-russian-ambassador-russias-hacking-military-supply-routes
- sekoia.comSekoiahttps://www.sekoia.com/blog/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/06/google-details-turlas-new-stockstay.html
- therecord.mediaThe Recordhttps://therecord.media/russia-turla-espionage-ukraine-stockstay-malware
- welivesecurity.comESET WeLiveSecurityhttps://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/