ATT&CKGroupsSea Turtle

Sea Turtle

G1041

Threat group.View on attack.mitre.org

About this group

Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.

Techniques used27

Procedure examples27

TechniqueProcedure example
T1027.004
Compile After Delivery

Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.

T1059.004
Unix Shell

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

T1071.001
Web Protocols

Sea Turtle connected over TCP using HTTP to establish command and control channels.

T1074.002
Remote Data Staging

Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.

T1078
Valid Accounts

Sea Turtle used compromised credentials to maintain long-term access to victim environments.

T1078.003
Local Accounts

Sea Turtle compromised cPanel accounts in victim environments.

T1114.001
Local Email Collection

Sea Turtle collected email archives from victim environments.

T1133
External Remote Services

Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations.

T1190
Exploit Public-Facing Application

Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns.

T1199
Trusted Relationship

Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.

T1203
Exploitation for Client Execution

Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution.

T1213.006
Databases

Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.

T1505.003
Web Shell

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.

T1557
Adversary-in-the-Middle

Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture.

T1560.001
Archive via Utility

Sea Turtle used the tar utility to create a local archive of email data on a victim system.

View all 27 procedure examples

Software1

Campaigns0

None recorded.

References4

  1. Hunt Sea Turtle 2024 Open source
    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.
  2. PWC Sea Turtle 2023 Open source
    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.
  3. Talos Sea Turtle 2019 Open source
    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.
  4. Talos Sea Turtle 2019_2 Open source
    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.