Sea Turtle
MISPUnknown
TR
Unknown
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has the potential to undermine the trust users have on the internet. That trust and the stability of the DNS system as a whole drives the global economy. Responsible nations should avoid targeting this system, work together to establish an accepted global norm that this system and the organizations that control it are off-limits, and cooperate in pursuing those actors who act irresponsibly by targeting this system.
Techniques Used (27)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1027.004 | Compile After Delivery | - |
| T1059.004 | Unix Shell | - |
| T1070.002 | Clear Linux or Mac System Logs | - |
| T1071.001 | Web Protocols | - |
| T1074.002 | Remote Data Staging | - |
| T1078 | Valid Accounts | - |
| T1078.003 | Local Accounts | - |
| T1114.001 | Local Email Collection | - |
| T1133 | External Remote Services | - |
| T1190 | Exploit Public-Facing Application | - |
| T1199 | Trusted Relationship | - |
| T1203 | Exploitation for Client Execution | - |
| T1213.006 | Databases | - |
| T1505.003 | Web Shell | - |
| T1557 | Adversary-in-the-Middle | - |
References (10)
- blog.talosintelligence.com - Seaturtle
- blog.talosintelligence.com - Sea Turtle Keeps On Swimming
- reuters.com - Exclusive Hackers Acting In Turkeys Interests Believed To Be Behind Recent Cyberattacks Sources IdUSKBN1ZQ10X
- icann.zoom.us - AhQB4AQyjCuEJGz2wQQans0Xqkz3su8swGLQoORJhdECw9ttz0TbuyzBlue85gIY
- community.icann.org - Cybersecurity%20and%20the%20ICANN%20Ecosystem.pdf
- pwc.co.uk - Cyber Threats 2019 Retrospect.pdf
- pwc.co.uk - Pwc Cyber Threats 2020 A Year In Retrospect.pdf
- domaintools.com - Finding Additional Indicators With Passive Dns Within Domaintools Iris
- go.crowdstrike.com - Report2022GTR.pdf
- query.prod.cms.rt.microsoft.com - RWMFIi
Aliases (945)
Related Malware (1)
Metadata
| ID: | 226 |
| Created: | 13/01/2026 17:48 |
| Updated: | 07/03/2026 04:00 |