G1041: Sea Turtle
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.[1][2][3][4]
Security context for executives and security teams
G1041: Sea Turtle describes [Sea Turtle](https://attack.mitre.org/groups/G1041) is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. [Sea Turtle](https://attack.mitre.org/groups/G1041) is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling [Sea Turtle](https://attack.mitre.org/groups/G1041...
Executive priority
G1041: Sea Turtle is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1041: Sea Turtle by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1041: Sea Turtle appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Sea Turtle
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1583 | Acquire Infrastructure | Sea Turtle accessed victim networks from VPN service provider networks.[4] |
| Enterprise | T1074.002 | Remote Data StagingSub-technique | Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.[4] |
| Enterprise | T1114.001 | Local Email CollectionSub-technique | Sea Turtle collected email archives from victim environments.[4] |
| Enterprise | T1583.002 | DNS ServerSub-technique | Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials.[2][1] |
| Enterprise | T1608.003 | Install Digital CertificateSub-technique | Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations.[1] |
| Enterprise | T1690 | Prevent Command History Logging | Sea Turtle unset the Bash and MySQL history files on victim systems.[4] |
| Enterprise | T1584.002 | DNS ServerSub-technique | Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups.[1][2] |
| Enterprise | T1583.003 | Virtual Private ServerSub-technique | Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture.[1] |
| Enterprise | T1588.004 | Digital CertificatesSub-technique | Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization.[1][2] |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | Sea Turtle used the tar utility to create a local archive of email data on a victim system.[4] |
| Enterprise | T1564.011 | Ignore Process InterruptsSub-technique | Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal.[4] |
| Enterprise | T1588.002 | ToolSub-technique | Sea Turtle has used tools such as Adminer during intrusions.[4] |
| Enterprise | T1190 | Exploit Public-Facing Application | Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns.[1][3] |
| Enterprise | T1078.003 | Local AccountsSub-technique | Sea Turtle compromised cPanel accounts in victim environments.[4] |
| Enterprise | T1203 | Exploitation for Client Execution | Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution.[3] |
| Enterprise | T1566 | Phishing | Sea Turtle used spear phishing to gain initial access to victims.[1] |
| Enterprise | T1133 | External Remote Services | Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations.[4] |
| Enterprise | T1213.006 | DatabasesSub-technique | Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.[4] |
| Enterprise | T1583.001 | DomainsSub-technique | Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers.[2][4] |
| Enterprise | T1027.004 | Compile After DeliverySub-technique | Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.[4] |
| Enterprise | T1685.006 | Clear Linux or Mac System LogsSub-technique | Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions.[4] |
| Enterprise | T1059.004 | Unix ShellSub-technique | Sea Turtle used shell scripts for post-exploitation execution in victim environments.[3][4] |
| Enterprise | T1505.003 | Web ShellSub-technique | Sea Turtle deployed the SnappyTCP web shell during intrusion operations.[3][4] |
| Enterprise | T1078 | Valid Accounts | Sea Turtle used compromised credentials to maintain long-term access to victim environments.[1] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | Sea Turtle connected over TCP using HTTP to establish command and control channels.[4] |
| Enterprise | T1199 | Trusted Relationship | Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.[1] |
| Enterprise | T1557 | Adversary-in-the-Middle | Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture.[1][2] |
Groups, software, and campaigns
S1163: SnappyTCP
SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims. SnappyTCP appears to be based on a public GitHub project that has since been removed from the code-sharing site. SnappyTCP includes a simple reverse TCP shell for Linux and Unix environments with basic command and control capabilities.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | ef43bcac57be… | ||
| 19.1 | 1.0 | Older bundle | 77a97b048f3a… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Talos Sea Turtle 2019
Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.
Open source URL - [2]Talos Sea Turtle 2019_2
Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.
Open source URL - [3]PWC Sea Turtle 2023
PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.
Open source URL - [4]Hunt Sea Turtle 2024
Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.
Open source URL - [5]Cosmic Wolf
(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
- [6]Marbled Dust
(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
- [7]Microsoft Digital Defense 2021
Microsoft. (2021, October). Microsoft Digital Defense Report. Retrieved November 20, 2024.
Open source URL - [8]SILICON
(Citation: Microsoft Digital Defense 2021)(Citation: Hunt Sea Turtle 2024)
- [9]Teal Kurma
(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
- [10]mitre-attackG1041Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
