1. Executive summary
On 13 July 2026, ANSSI (via the French Cyber Crisis Coordination Centre, C4) published a CTI advisory reporting the targeting and compromise of French entities using the Turla intrusion set. The advisory states that Turla is operated by the 16th Centre of the Federal Security Service of the Russian Federation (FSB) and has been active since at least 2004 for intelligence-gathering against strategic entities and individuals worldwide. French victimology includes ministries and entities in the diplomatic, defence, justice, and technology sectors. The activity was formally attributed to Russia on the same date by the French Minister for Europe and Foreign Affairs and by the EU High Representative for Foreign Affairs and Security Policy. EMEA financial services firms with operations, supply-chain links, or third-party relationships in France should treat this as a credible state-level espionage threat relevant to strategic intelligence collection.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | Confirmed compromise of French entities by a state-level intrusion set engaged in intelligence-gathering. | Financial entities with French operations or third-party dependencies must ensure their incident management process can detect and respond to APT-class intrusion activity, not just commodity malware. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A named, state-attributed cyber threat (Turla/FSB) with confirmed compromises. | Incidents matching this pattern should be classified at a severity tier reflecting state-level espionage impact, triggering corresponding reporting and response escalations. |
| DORA Art. 28: ICT third-party risk — general principles | French entities in the diplomatic, defence, justice, and technology sectors are confirmed targets; financial services firms with French ICT third-party providers share this threat surface. | Review third-party risk exposure to French-based providers in targeted sectors; assess whether providers have detection coverage for Turla-class tradecraft. |
| NIS2 Art. 21(2)(d): supply chain security measures | State-level intrusion set targeting entities in France, including technology-sector organisations that may sit in the supply chain of financial services. | In-scope NIS2 entities should evaluate supply-chain exposure to compromised French technology-sector providers and incorporate Turla threat intelligence into supplier risk assessments. |
| UK NIS 2018: UK Network and Information Systems Regulations — OES/RDSP duties | NATO and EU member states are confirmed targets of ongoing Turla espionage campaigns; UK OES/RDSP operators with French linkages share the threat surface. | UK operators of essential services and relevant digital service providers should assess whether their threat modelling and detection capabilities account for Turla-class state espionage activity. |
3. Technical analysis & attack chain
Attribution caveat: The advisory attributes Turla to the "16th Centre of the Federal Security Service of the Russian Federation (FSB)." In the verified reference data, actor "Turla" maps to MITRE ATT&CK G0010. Actor "FSB" has no MITRE ATT&CK profile; the FSB-level attribution is therefore treated as unconfirmed at the MITRE-mapped layer. The French government and EU High Representative issued formal attribution statements on 13 July 2026.
Confirmed attack chain
- Strategic targeting — Turla has been operational since at least 2004, targeting strategic entities and individuals worldwide for intelligence-gathering purposes. French victimology includes ministries and entities in the diplomatic, defence, justice, and technology sectors.
- Ongoing campaign context — Espionage campaigns associated with Turla against Ukraine, NATO countries, and EU member states continue in the context of Russia's war of aggression launched on 24 February 2022.
- Compromise — The advisory confirms both targeting and compromise of French entities (not merely attempted access). No further technical detail on the compromise mechanism is provided in the source material.
Technical detail available in the source
The source material is a high-level CTI/advisory note rather than a technical deep-dive report. It does not provide:
- Specific CVEs exploited for initial access
- Malware family names, file hashes, or filenames
- C2 infrastructure (domains, IPs, protocols)
- Persistence mechanisms, registry keys, or scheduled tasks
- Lateral movement techniques or tools
- Data exfiltration methods or staging details
The advisory references a downloadable full report ("Targeting and Compromise of French Entities Using the Turla Intrusion Set") which may contain additional technical detail. This advisory is based solely on the published web content of CERTFR-2026-CTI-005 and the related CERTFR-2026-CTI-004. Single-sourced; verify before enforcement — all operational detail rests on the ANSSI/C4 publication alone.
4. Mitigation & containment
Given the absence of specific technical indicators in the source material, mitigation guidance is threat-informed rather than IOC-driven.
P1 — Within 24 hours
- Brief your SOC/CTI team on the ANSSI advisory (CERTFR-2026-CTI-005) and the formal French/EU attribution statements.
- Assess whether your organisation has operations, subsidiaries, or key personnel in France — particularly in the diplomatic, defence, justice, or technology sectors — and elevate monitoring for those environments.
- Review threat-intel feeds for Turla/G0010 IOCs from prior public reports (CISA, NCSC, FBI, Mandiant, ESET, Kaspersky) and ensure they are deployed to detection tooling. The ANSSI advisory itself does not provide IOCs.
- Check whether any French-based ICT third-party providers in your supply chain are in the targeted sector categories and contact them for assurance.
P2 — Within 72 hours
- Download and review the full ANSSI technical report linked from the advisory page for IOCs, YARA rules, and detection guidance not present in the summary web content.
- Map Turla known TTPs (MITRE ATT&CK G0010) against your current detection coverage. Historical Turla tradecraft includes: compromised legitimate websites for watering-hole attacks, browser exploitation, PowerShell-based loaders, named pipe-based C2, and abuse of legitimate cloud services for C2. Prioritise gaps.
- Ensure EDR is deployed across all endpoints in French operations and that alerting for living-off-the-land binary abuse is tuned.
P3 — Within 7 days
- Conduct a targeted hunt in French-environment logs for Turla-associated behavioural patterns using MITRE G0010 technique references.
- Review and tighten egress filtering on French operations to limit C2 channels over legitimate cloud services.
- Update your incident response playbooks to include a state-level espionage scenario reflecting this advisory, aligned with DORA Art. 17 and Art. 18 classification thresholds.
- If a compromise is identified, prepare for DORA Art. 19 major-incident reporting and NIS2 Art. 23 incident reporting obligations.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
Threat actor context
Turla · G0010 · aka IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. …
No MITRE ATT&CK profile for: FSB.
7. Sources
- ANSSI / CERT-FR, "Targeting and Compromise of French Entities Using the Turla Intrusion Set (13 juillet 2026)," https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/, published 2026-07-13.
- ANSSI / CERT-FR, "Ciblage et compromission d'entités françaises au moyen du mode opératoire d'attaque Turla (13 juillet 2026)," https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-004/, published 2026-07-13.
- French Ministry for Europe and Foreign Affairs, attribution statement, https://www.diplomatie.gouv.fr/fr/presse-et-ressources/decouvrir-et-informer/actualites/attribution-a-la-russie-d-activites-cyber-malveillantes-a-des-fins-d-espionnage-en-france, published 2026-07-13.
8. Adverse Trace position
This is a confirmed, state-attributed espionage campaign by a high-capability intrusion set (Turla, MITRE G0010) targeting French strategic entities, with formal attribution by both France and the EU on 13 July 2026. The FSB-level attribution is unconfirmed at the MITRE-mapped layer (no MITRE profile for "FSB" in verified reference data). The source material is a strategic advisory without technical indicators, so immediate defensive action should be threat-informed: brief SOCs, assess French operational and third-party exposure, retrieve the full downloadable ANSSI report for technical detail, and hunt against known Turla TTPs from prior public reporting. EMEA financial services clients with French operations, personnel, or supply-chain dependencies face elevated risk of intelligence-gathering intrusion. Adverse Trace will update this advisory if the full ANSSI technical report or subsequent publications provide IOCs, YARA rules, or additional attack-chain detail. Confidence caveat: single-sourced (ANSSI/C4); verify before enforcement.
Published via PulseTrace — Adverse Trace threat intelligence.