Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupSea Turtle | Sea Turtle used compromised credentials to maintain long-term access to victim environments. |
| T1190 Exploit Public-Facing Application |
GroupSea Turtle | Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns. |
| T1199 Trusted Relationship |
GroupSea Turtle | Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers. |
| T1557 Adversary-in-the-Middle |
GroupSea Turtle | Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture. |
| T1566 Phishing |
GroupSea Turtle | Sea Turtle used spear phishing to gain initial access to victims. |
| T1583.002 DNS Server |
GroupSea Turtle | Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials. |
| T1583.003 Virtual Private Server |
GroupSea Turtle | Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture. |
| T1584.002 DNS Server |
GroupSea Turtle | Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups. |
| T1588.004 Digital Certificates |
GroupSea Turtle | Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization. |
| T1608.003 Install Digital Certificate |
GroupSea Turtle | Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.