Threat group.View on attack.mitre.org
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.
| Technique | Procedure example |
|---|---|
| T1027.004 Compile After Delivery |
Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments. |
| T1059.004 Unix Shell |
Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| T1071.001 Web Protocols |
Sea Turtle connected over TCP using HTTP to establish command and control channels. |
| T1074.002 Remote Data Staging |
Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet. |
| T1078 Valid Accounts |
Sea Turtle used compromised credentials to maintain long-term access to victim environments. |
| T1078.003 Local Accounts |
Sea Turtle compromised cPanel accounts in victim environments. |
| T1114.001 Local Email Collection |
Sea Turtle collected email archives from victim environments. |
| T1133 External Remote Services |
Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations. |
| T1190 Exploit Public-Facing Application |
Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns. |
| T1199 Trusted Relationship |
Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers. |
| T1203 Exploitation for Client Execution |
Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution. |
| T1213.006 Databases |
Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines. |
| T1505.003 Web Shell |
Sea Turtle deployed the SnappyTCP web shell during intrusion operations. |
| T1557 Adversary-in-the-Middle |
Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture. |
| T1560.001 Archive via Utility |
Sea Turtle used the tar utility to create a local archive of email data on a victim system. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.