ATT&CKReferencesHunt Sea Turtle 2024

Hunt Sea Turtle 2024

Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1027.004
Compile After Delivery
GroupSea Turtle

Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.

T1059.004
Unix Shell
GroupSea Turtle

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

T1071.001
Web Protocols
GroupSea Turtle

Sea Turtle connected over TCP using HTTP to establish command and control channels.

T1074.002
Remote Data Staging
GroupSea Turtle

Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.

T1078.003
Local Accounts
GroupSea Turtle

Sea Turtle compromised cPanel accounts in victim environments.

T1114.001
Local Email Collection
GroupSea Turtle

Sea Turtle collected email archives from victim environments.

T1133
External Remote Services
GroupSea Turtle

Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations.

T1213.006
Databases
GroupSea Turtle

Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.

T1505.003
Web Shell
GroupSea Turtle

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.

T1560.001
Archive via Utility
GroupSea Turtle

Sea Turtle used the tar utility to create a local archive of email data on a victim system.

T1564.011
Ignore Process Interrupts
GroupSea Turtle

Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal.

T1583
Acquire Infrastructure
GroupSea Turtle

Sea Turtle accessed victim networks from VPN service provider networks.

T1583.001
Domains
GroupSea Turtle

Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers.

T1588.002
Tool
GroupSea Turtle

Sea Turtle has used tools such as Adminer during intrusions.

T1685.006
Clear Linux or Mac System Logs
GroupSea Turtle

Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions.

T1690
Prevent Command History Logging
GroupSea Turtle

Sea Turtle unset the Bash and MySQL history files on victim systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.