Sea Turtle
MISPUnknown
TR
Unknown
[Sea Turtle](https://attack.mitre.org/groups/G1041) is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. [Sea Turtle](https://attack.mitre.org/groups/G1041) is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling [Sea Turtle](https://attack.mitre.org/groups/G1041) to spoof log in portals and other applications for credential collection.(Citation: Talos Sea Turtle 2019)(Citation: Talos Sea Turtle 2019_2)(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
Tecniche Utilizzate (27)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1027.004 | Compile After Delivery | - |
| T1059.004 | Unix Shell | - |
| T1070.002 | Clear Linux or Mac System Logs | - |
| T1071.001 | Web Protocols | - |
| T1074.002 | Remote Data Staging | - |
| T1078 | Valid Accounts | - |
| T1078.003 | Local Accounts | - |
| T1114.001 | Local Email Collection | - |
| T1133 | External Remote Services | - |
| T1190 | Exploit Public-Facing Application | - |
| T1199 | Trusted Relationship | - |
| T1203 | Exploitation for Client Execution | - |
| T1213.006 | Databases | - |
| T1505.003 | Web Shell | - |
| T1557 | Adversary-in-the-Middle | - |
Riferimenti (10)
- blog.talosintelligence.com - Seaturtle
- blog.talosintelligence.com - Sea Turtle Keeps On Swimming
- reuters.com - Exclusive Hackers Acting In Turkeys Interests Believed To Be Behind Recent Cyberattacks Sources IdUSKBN1ZQ10X
- icann.zoom.us - AhQB4AQyjCuEJGz2wQQans0Xqkz3su8swGLQoORJhdECw9ttz0TbuyzBlue85gIY
- community.icann.org - Cybersecurity%20and%20the%20ICANN%20Ecosystem.pdf
- pwc.co.uk - Cyber Threats 2019 Retrospect.pdf
- pwc.co.uk - Pwc Cyber Threats 2020 A Year In Retrospect.pdf
- domaintools.com - Finding Additional Indicators With Passive Dns Within Domaintools Iris
- go.crowdstrike.com - Report2022GTR.pdf
- query.prod.cms.rt.microsoft.com - RWMFIi
Alias (931)
Malware Utilizzato (1)
Metadata
| ID: | 226 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |