Sea Turtle — APT Profile
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.Also tracked as
Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
Tools & malware
- SnappyTCP Backdoor
Vendor research
- Microsoft Digital Defense Report Microsoft
- Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service Talos
- Turkish espionage campaigns in the Netherlands Hunt
- Microsoft Digital Defense Report Microsoft
- Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques Talos
- The Tortoise and The Malware PWC