Sea Turtle
MITRE ATT&CK: G1041 View on attack.mitre.org
Aliases: Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON, COSMIC WOLF, UNC1326, Sea Turtle
- First seen
- 2017-01-01 00:00:00
- Origin
- TR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:33:19
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:tr country_code:ae country_code:gr country_code:cy country_code:us country_code:fr country_code:qa
Context
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.
Detection coverage
- 2 YARA rules
- 268 Sigma rules
Malware & tools used
- Acquire Infrastructure (attack-pattern)
- Remote Data Staging (attack-pattern)
- Local Email Collection (attack-pattern)
- DNS Server (attack-pattern)
- Install Digital Certificate (attack-pattern)
- Prevent Command History Logging (attack-pattern)
- DNS Server (attack-pattern)
- Virtual Private Server (attack-pattern)
- Digital Certificates (attack-pattern)
- Archive via Utility (attack-pattern)
- Ignore Process Interrupts (attack-pattern)
- Tool (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Local Accounts (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Phishing (attack-pattern)
- External Remote Services (attack-pattern)
- Databases (attack-pattern)
- Domains (attack-pattern)
- Compile After Delivery (attack-pattern)
- Clear Linux or Mac System Logs (attack-pattern)
- Unix Shell (attack-pattern)
- Web Shell (attack-pattern)
- Valid Accounts (attack-pattern)
- Web Protocols (attack-pattern)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Cisco Talos — Seaturtle (report)
- Cisco Talos — Sea Turtle Keeps On Swimming (report)
- reuters.com — Exclusive Hackers Acting In Turkeys Interests Believed To Be Behind Recent Cyberattacks Sources Iduskbn1Zq10X (report)
- icann.zoom.us — Ahqb4Aqyjcuejgz2Wqqans0Xqkz3Su8Swglqoorjhdecw9Ttz0Tbuyzblue85Giy (report)
- community.icann.org — Cybersecurity%20And%20The%20Icann%20Ecosystem (report)
- domaintools.com — Finding Additional Indicators With Passive Dns Within Domaintools Iris (report)
- CrowdStrike — Report2022Gtr (report)
- Microsoft — Rwmfii (report)
- threatintel.eu — On Sea Turtle Campaign Targeting Greek Governmental Organisations Timeline (report)
- Mandiant — Global Dns Hijacking Campaign Dns Record Manipulation At Scale (report)
- virusbulletin.com — Vb2019 Mercer Rascagneres (report)
- youtube.com — Watch (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G1041 (report)
- Cisco Talos — Seaturtle (report)
- huntandhackett.com — Turkish Espionage Campaigns (report)
- pwc.com — Tortoise And Malwahare (report)
Attributed from
- Marbled Dust Output Messenger Zero-Day Attack (campaign)
External references
- mitre-attack — G1041
- SILICON
- Teal Kurma
- Marbled Dust
- Cosmic Wolf
- Talos Sea Turtle 2019
- Hunt Sea Turtle 2024
- Microsoft Digital Defense 2021
- Talos Sea Turtle 2019_2
- PWC Sea Turtle 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy