ATT&CKReferencesPWC Sea Turtle 2023

PWC Sea Turtle 2023

PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1059.004
Unix Shell
MalwareSnappyTCP

SnappyTCP creates the reverse shell using a pthread spawning a bash shell.

T1059.004
Unix Shell
GroupSea Turtle

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

T1071.001
Web Protocols
MalwareSnappyTCP

SnappyTCP connects to the command and control server via a TCP socket using HTTP.

T1095
Non-Application Layer Protocol
MalwareSnappyTCP

SnappyTCP spawns a reverse TCP shell following an HTTP-based negotiation.

T1190
Exploit Public-Facing Application
GroupSea Turtle

Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns.

T1203
Exploitation for Client Execution
GroupSea Turtle

Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution.

T1505.003
Web Shell
GroupSea Turtle

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.

T1505.003
Web Shell
MalwareSnappyTCP

SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes.

T1573.002
Asymmetric Cryptography
MalwareSnappyTCP

SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.