Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1557 Adversary-in-the-Middle |
GroupSea Turtle | Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture. |
| T1583.001 Domains |
GroupSea Turtle | Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers. |
| T1583.002 DNS Server |
GroupSea Turtle | Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials. |
| T1584.002 DNS Server |
GroupSea Turtle | Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups. |
| T1588.004 Digital Certificates |
GroupSea Turtle | Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.