Also known as: Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON, UNC1326
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.(Citation: Talos Sea Turtle 2019)(Citation: Talos Sea Turtle 2019_2)(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
Sea Turtle
Targeted Sectors
Executive Summary
Sea Turtle is a Turkey-linked threat actor known for conducting espionage and service provider compromise operations since at least 2017. The group has targeted critical sectors including energy, defense, and government, employing sophisticated tactics such as DNS hijacking to enable credential collection and phishing activities.
Goals & Targeting
Sea Turtle's primary strategic objective appears to be gathering sensitive information and intelligence through espionage activities, targeting sectors such as energy, defense, and government. The group's targeting profile suggests a focus on industries that hold critical infrastructure and geopolitical significance. While the specific countries targeted are not fully detailed in the available data, the actor's global operational footprint and Turkey-linked nature imply a potential interest in regional or international security and economic interests.
Enhanced Description
Sea Turtle operates with a focus on espionage and compromising service providers, particularly targeting registrars managing country-code top-level domains (ccTLDs) and conducting complex DNS-based intrusions. The actor is notable for exploiting DNS resolution to spoof login portals and other applications, facilitating credential theft. Sea Turtle's activities have been observed across multiple regions, including Asia, Europe, and North America. Linked intelligence indicates the group employs tools like SnappyTCP and exhibits a preference for compromising infrastructure to facilitate long-term operations. The actor's operational tradecraft includes the use of web shells for persistence and exploitation of public-facing applications, as well as leveraging digital certificates and clearing system logs to avoid detection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Sea Turtle has been involved in multiple campaigns, including operations targeting the Netherlands and other countries. The actor is known for its patient and targeted approach to compromising domains and infrastructure, often using registered domains for command-and-control (C2) communication. Campaigns have included phishing activities leveraging legitimate-looking domains and IP addresses, as well as exploitation of web services for persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a moderate level of confidence in the data provided, primarily based on linked intelligence from reputable sources (Talos, PWC). The actor's operational strategy and tools are partially documented, but gaps exist regarding detailed TTP descriptions beyond DNS hijacking. Additionally, the exact targeting criteria for countries and specific campaigns remain somewhat unclear.
Sea Turtle
No observed data linked yet.
27
Techniques
10
Tools
2
Campaigns
91
IOCs
0
Observed Data
9
Tactics