Sea Turtle
Also tracked as Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.
- Documented techniques
- 27
- Assessed motivation
- Espionage
- First seen
- 2017
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development8
credential access1
collection4
command and control1
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.