Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.004 Compile After Delivery |
GroupSea Turtle | Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments. |
| T1059.004 Unix Shell |
GroupSea Turtle | Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| T1071.001 Web Protocols |
GroupSea Turtle | Sea Turtle connected over TCP using HTTP to establish command and control channels. |
| T1074.002 Remote Data Staging |
GroupSea Turtle | Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet. |
| T1078.003 Local Accounts |
GroupSea Turtle | Sea Turtle compromised cPanel accounts in victim environments. |
| T1114.001 Local Email Collection |
GroupSea Turtle | Sea Turtle collected email archives from victim environments. |
| T1133 External Remote Services |
GroupSea Turtle | Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations. |
| T1213.006 Databases |
GroupSea Turtle | Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines. |
| T1505.003 Web Shell |
GroupSea Turtle | Sea Turtle deployed the SnappyTCP web shell during intrusion operations. |
| T1560.001 Archive via Utility |
GroupSea Turtle | Sea Turtle used the tar utility to create a local archive of email data on a victim system. |
| T1564.011 Ignore Process Interrupts |
GroupSea Turtle | Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal. |
| T1583 Acquire Infrastructure |
GroupSea Turtle | Sea Turtle accessed victim networks from VPN service provider networks. |
| T1583.001 Domains |
GroupSea Turtle | Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers. |
| T1588.002 Tool |
GroupSea Turtle | Sea Turtle has used tools such as Adminer during intrusions. |
| T1685.006 Clear Linux or Mac System Logs |
GroupSea Turtle | Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions. |
| T1690 Prevent Command History Logging |
GroupSea Turtle | Sea Turtle unset the Bash and MySQL history files on victim systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.