Sea Turtle

MITRE ATT&CK: G1041 View on attack.mitre.org

Aliases: Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON, COSMIC WOLF, UNC1326, Sea Turtle

First seen
2017-01-01 00:00:00
Origin
TR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:33:19

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:tr country_code:ae country_code:gr country_code:cy country_code:us country_code:fr country_code:qa

Context

Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.

Detection coverage

  • 2 YARA rules
  • 268 Sigma rules

Malware & tools used

  • Acquire Infrastructure (attack-pattern)
  • Remote Data Staging (attack-pattern)
  • Local Email Collection (attack-pattern)
  • DNS Server (attack-pattern)
  • Install Digital Certificate (attack-pattern)
  • Prevent Command History Logging (attack-pattern)
  • DNS Server (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • Digital Certificates (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Ignore Process Interrupts (attack-pattern)
  • Tool (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Local Accounts (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Phishing (attack-pattern)
  • External Remote Services (attack-pattern)
  • Databases (attack-pattern)
  • Domains (attack-pattern)
  • Compile After Delivery (attack-pattern)
  • Clear Linux or Mac System Logs (attack-pattern)
  • Unix Shell (attack-pattern)
  • Web Shell (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Web Protocols (attack-pattern)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Cisco Talos — Seaturtle (report)
  • Cisco Talos — Sea Turtle Keeps On Swimming (report)
  • reuters.com — Exclusive Hackers Acting In Turkeys Interests Believed To Be Behind Recent Cyberattacks Sources Iduskbn1Zq10X (report)
  • icann.zoom.us — Ahqb4Aqyjcuejgz2Wqqans0Xqkz3Su8Swglqoorjhdecw9Ttz0Tbuyzblue85Giy (report)
  • community.icann.org — Cybersecurity%20And%20The%20Icann%20Ecosystem (report)
  • domaintools.com — Finding Additional Indicators With Passive Dns Within Domaintools Iris (report)
  • CrowdStrike — Report2022Gtr (report)
  • Microsoft — Rwmfii (report)
  • threatintel.eu — On Sea Turtle Campaign Targeting Greek Governmental Organisations Timeline (report)
  • Mandiant — Global Dns Hijacking Campaign Dns Record Manipulation At Scale (report)
  • virusbulletin.com — Vb2019 Mercer Rascagneres (report)
  • youtube.com — Watch (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G1041 (report)
  • Cisco Talos — Seaturtle (report)
  • huntandhackett.com — Turkish Espionage Campaigns (report)
  • pwc.com — Tortoise And Malwahare (report)

Attributed from

  • Marbled Dust Output Messenger Zero-Day Attack (campaign)

External references