Sea Turtle
Also tracked as Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.
- Known attack methods
- 27
- Motive
- Espionage
- First seen
- 2017
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques
Resource Development
9 techniques · 4 used
Initial Access
11 techniques · 3 used
Execution
20 techniques · 2 used
Persistence
22 techniques · 2 used
Privilege Escalation
13 techniques
Stealth
30 techniques · 3 used
Defense Impairment
18 techniques · 2 used
Credential Access
17 techniques · 1 used
Discovery
34 techniques
Lateral Movement
9 techniques
Collection
17 techniques · 4 used
Command and Control
18 techniques · 1 used
Exfiltration
9 techniques
Impact
15 techniques
Resource development8
Persistence2
Stealth4
Defense impairment2
Credential access1
Collection4
Command and control1
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.