Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Sea Turtle

Also known as: Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON, UNC1326

Description

Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.(Citation: Talos Sea Turtle 2019)(Citation: Talos Sea Turtle 2019_2)(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

TTP Summary

Sea Turtle

Goals & Targeting

Targeted Sectors

Energy
Defense
Government

AI Analysis

· 1 week ago

Executive Summary

Sea Turtle is a Turkey-linked threat actor known for conducting espionage and service provider compromise operations since at least 2017. The group has targeted critical sectors including energy, defense, and government, employing sophisticated tactics such as DNS hijacking to enable credential collection and phishing activities.

Goals & Targeting

Sea Turtle's primary strategic objective appears to be gathering sensitive information and intelligence through espionage activities, targeting sectors such as energy, defense, and government. The group's targeting profile suggests a focus on industries that hold critical infrastructure and geopolitical significance. While the specific countries targeted are not fully detailed in the available data, the actor's global operational footprint and Turkey-linked nature imply a potential interest in regional or international security and economic interests.

Enhanced Description

Sea Turtle operates with a focus on espionage and compromising service providers, particularly targeting registrars managing country-code top-level domains (ccTLDs) and conducting complex DNS-based intrusions. The actor is notable for exploiting DNS resolution to spoof login portals and other applications, facilitating credential theft. Sea Turtle's activities have been observed across multiple regions, including Asia, Europe, and North America. Linked intelligence indicates the group employs tools like SnappyTCP and exhibits a preference for compromising infrastructure to facilitate long-term operations. The actor's operational tradecraft includes the use of web shells for persistence and exploitation of public-facing applications, as well as leveraging digital certificates and clearing system logs to avoid detection.

Key Capabilities

  • DNS provider compromise to hijack DNS resolution
  • Spoofing login portals and application pages for credential collection
  • Exploitation of service providers and ccTLD registrars
  • Use of web shells for persistence
  • Employment of SnappyTCP toolset
  • Sophisticated campaign planning with long-term operational presence

MITRE ATT&CK Tactics

Intrusion
Collection
Exfiltration
Impact
Initial Access
Defense-Evasion
Disruption

ATT&CK Techniques

T1560.001
T1583
T1133
T1213.006
T1074.002
T1114.001
T1190
T1583.001
T1583.002
T1059.004
T1078.001
T1685.006
T1588.002
T1071.001
T1557

Software / Tooling

SnappyTCP

Campaigns & Victims

Sea Turtle has been involved in multiple campaigns, including operations targeting the Netherlands and other countries. The actor is known for its patient and targeted approach to compromising domains and infrastructure, often using registered domains for command-and-control (C2) communication. Campaigns have included phishing activities leveraging legitimate-looking domains and IP addresses, as well as exploitation of web services for persistence.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments targeting sector-specific personnel
  • Compromise of DNS providers to enable domain theft and phishing campaigns
  • Use of specific IP addresses associated with known Sea Turtle campaigns (e.g., 82.102.19.88)
  • Registration of malicious domains for C2 communication (e.g., lo0.systemctl.network, forward.boord.info)
  • Presence of web shells in targeted systems

Recommended Actions

  • Monitor DNS resolution and domain registration activities for unauthorized changes
  • Implement multi-factor authentication for critical systems and applications
  • Conduct regular network perimeter security audits to identify potential beachheads for compromise
  • Deploy network traffic analysis tools to detect anomalies indicative of Sea Turtle's TTPs
  • Educate users about phishing attempts leveraging spoofed login pages
  • Secure web services against known exploitation techniques (e.g., CVEs linked to T1203)

Suggested Tags

APT
Espionage
Energy Sector
Defense Sector
Government
DNS-Based Threats

Confidence Assessment

There is a moderate level of confidence in the data provided, primarily based on linked intelligence from reputable sources (Talos, PWC). The actor's operational strategy and tools are partially documented, but gaps exist regarding detailed TTP descriptions beyond DNS hijacking. Additionally, the exact targeting criteria for countries and specific campaigns remain somewhat unclear.

ATT&CK Techniques

Resource Development
8 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 11 Domain 9

References

  1. Talos Sea Turtle 2019 — Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.
  2. Hunt Sea Turtle 2024 — Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.
  3. Microsoft Digital Defense 2021 — Microsoft. (2021, October). Microsoft Digital Defense Report. Retrieved November 20, 2024.
  4. Talos Sea Turtle 2019_2 — Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.
  5. PWC Sea Turtle 2023 — PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

Intel Summary

27

Techniques

10

Tools

2

Campaigns

91

IOCs

0

Observed Data

9

Tactics

Tags

APT
Espionage
Energy Sector
Defense Sector
Government
DNS-Based Threats

Details

MITRE ID
G1041
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
T
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--56a05d27-4d47-418a-b330-781c5614f202
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.