Menu
Browse
Date:

Jul 2017

Location:

Switzerland

Summary

Switzerland's defence ministry successfully thwarted a cyber attack employing malware resembling the Turla spyware family, detected during routine monitoring. The intrusion attempt triggered immediate countermeasures by government specialists, though authorities withheld details regarding the attack's origin or potential impacts such as data compromise, citing security protocols. An ongoing investigation was initiated alongside criminal charges filed against unidentified perpetrators. The Turla malware, previously linked to widespread infections targeting government and military systems across multiple regions, was suspected in this incident but no operational damage was confirmed.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Swiss Federal Department of Defense, Civil Protection and Sports detected a cyber attack targeting its systems in July 2017. Government specialists identified malware exhibiting operational characteristics consistent with the Turla malware family, which had been previously documented in global cyber espionage campaigns. The attack was discovered through defensive monitoring systems, though specific technical details about the intrusion vector or compromised systems were not disclosed. Swiss authorities implemented immediate countermeasures to neutralize the threat and secure affected infrastructure. No official statements confirmed whether data exfiltration or operational disruptions occurred during the incident. The government declined to attribute the attack to any specific threat actor or nation-state, citing ongoing security considerations. Federal prosecutors initiated criminal proceedings against unidentified perpetrators following standard legal protocols for cyber incidents.

Cyber Incident Image

Security researchers noted that Turla malware had been associated with sophisticated espionage operations since at least 2014, with historical attacks targeting government and military entities across Europe and the Middle East. Multiple independent analyses by cybersecurity firms and Western intelligence agencies had previously suggested potential links between Turla operations and Russian state-sponsored actors, though Swiss authorities did not endorse these assessments in their public communications. The incident prompted an ongoing internal investigation to determine the full scope of compromise and enhance defensive capabilities. No collateral damage to civilian infrastructure or allied systems was reported in connection with this event. The ministry maintained standard operational continuity throughout the response period while restricting public disclosure to minimal factual updates.

Sources
Sources available to members
1 source