LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1041: Sea Turtle

Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.[1][2][3][4]

EnterpriseG1041GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Sea Turtle matters because the ATT&CK record describes a threat actor focused on espionage and service-provider compromise, especially DNS registrars, ccTLD-related organizations, and DNS providers. The business risk is not limited to one server being compromised: DNS manipulation can redirect users to spoofed portals and enable credential collection against downstream victims. For executives, this makes DNS governance, third-party access, identity monitoring, and incident response readiness central control areas rather than purely technical infrastructure concerns.

Executive priority

Prioritize questions about who can change DNS records, which registrars and DNS providers are trusted, how those changes are approved and logged, and whether incident teams can rapidly validate DNS integrity during a suspected compromise. Because the ATT&CK relationships include valid accounts, trusted relationships, public-facing application exploitation, phishing, web shells, adversary-in-the-middle activity, and data collection, leaders should treat this as a cross-functional resilience issue spanning identity, vendor risk, SOC visibility, and crisis response evidence.

Technical view

ATT&CK does not provide a dedicated detection section for Sea Turtle, so defenders should validate coverage from the associated behaviors. Focus on monitoring DNS administration and registrar activity, authentication to external remote services and identity providers, public-facing Linux/Unix and web infrastructure, web shell persistence, Unix shell execution, web-protocol command-and-control, archive and staging activity, and collection from email or databases where applicable. Relationship context also identifies SnappyTCP as a Linux/Unix reverse TCP shell used by Sea Turtle between 2021 and 2023, so Linux web server and network egress telemetry are especially important where those systems are in scope.

Likely telemetry

  • DNS registrar, authoritative DNS, and DNS provider change logs, including record changes, account changes, and delegation changes
  • Identity provider, VPN, remote access, and privileged account authentication logs
  • Web server access logs, file integrity monitoring, and process execution telemetry for public-facing applications
  • Linux/Unix shell command history or endpoint telemetry where available
  • Network egress metadata for unusual HTTP/S, WebSocket, reverse TCP, or DNS-related activity

Detection direction

  • Baseline and alert on DNS record, name server, registrar account, and delegation changes, especially outside approved change windows or by unusual accounts.
  • Correlate DNS changes with identity events, remote service logins, phishing reports, and public-facing application alerts rather than treating DNS administration as isolated infrastructure noise.
  • Hunt for web shell indicators through unexpected files in web roots, unusual child processes spawned by web services, and command execution from web server contexts.
  • Review Linux/Unix systems for suspicious shell execution, reverse shell-like network connections, persistence artifacts, and processes that ignore interrupts or survive session termination.
  • Tune detections for valid-account abuse by emphasizing impossible travel, new device or infrastructure use, atypical administrative actions, and access through trusted relationships.

Mitigation priorities

  • Establish strong governance for DNS and registrar administration: least privilege, multi-person approval for critical changes, MFA, logging, and periodic review of authorized accounts.
  • Reduce trusted-relationship risk by inventorying third-party access paths, limiting privileges, enforcing strong authentication, and ensuring provider activity is logged and reviewable.
  • Harden public-facing applications and web servers through timely vulnerability management, configuration review, and monitoring for unauthorized file changes or web shell behavior.
  • Strengthen identity controls for valid accounts and local accounts, including credential hygiene, password reuse reduction, privileged access review, and alerting on abnormal use.
  • Prepare incident response procedures for DNS hijacking scenarios, including rapid record validation, registrar escalation contacts, credential reset sequencing, and communication plans.
Additional notes and limits

The most decision-relevant aspect of this object is the DNS and service-provider compromise theme. The associated techniques broaden the defensive view: initial access may involve phishing, public-facing application exploitation, external remote services, or trusted relationships; persistence may involve valid accounts or web shells; collection may involve email, databases, staging, and archiving; command and control may blend with web protocols. This supports a control validation exercise across DNS administration, identity, external attack surface, and Linux/Unix web infrastructure.

ATT&CK provides no official detection text, no group-level platforms, and no tactics directly on the intrusion-set object. Platform and tactic guidance here is derived only from the supplied relationships and should be validated against the local environment. The record supports Türkiye-linked attribution and historical activity since at least 2017, but this take does not assert current exploitation, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Sea Turtle

Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

27 rows
DomainIDNameRelationship / procedure
EnterpriseT1583Acquire Infrastructure

Sea Turtle accessed victim networks from VPN service provider networks.[4]

EnterpriseT1074.002Remote Data StagingSub-technique

Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.[4]

EnterpriseT1114.001Local Email CollectionSub-technique

Sea Turtle collected email archives from victim environments.[4]

EnterpriseT1583.002DNS ServerSub-technique

Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials.[2][1]

EnterpriseT1608.003Install Digital CertificateSub-technique

Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations.[1]

EnterpriseT1690Prevent Command History Logging

Sea Turtle unset the Bash and MySQL history files on victim systems.[4]

EnterpriseT1584.002DNS ServerSub-technique

Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups.[1][2]

EnterpriseT1583.003Virtual Private ServerSub-technique

Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture.[1]

EnterpriseT1588.004Digital CertificatesSub-technique

Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization.[1][2]

EnterpriseT1560.001Archive via UtilitySub-technique

Sea Turtle used the tar utility to create a local archive of email data on a victim system.[4]

EnterpriseT1564.011Ignore Process InterruptsSub-technique

Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal.[4]

EnterpriseT1588.002ToolSub-technique

Sea Turtle has used tools such as Adminer during intrusions.[4]

EnterpriseT1190Exploit Public-Facing Application

Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns.[1][3]

EnterpriseT1078.003Local AccountsSub-technique

Sea Turtle compromised cPanel accounts in victim environments.[4]

EnterpriseT1203Exploitation for Client Execution

Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution.[3]

EnterpriseT1566Phishing

Sea Turtle used spear phishing to gain initial access to victims.[1]

EnterpriseT1133External Remote Services

Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations.[4]

EnterpriseT1213.006DatabasesSub-technique

Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.[4]

EnterpriseT1583.001DomainsSub-technique

Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers.[2][4]

EnterpriseT1027.004Compile After DeliverySub-technique

Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.[4]

EnterpriseT1685.006Clear Linux or Mac System LogsSub-technique

Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions.[4]

EnterpriseT1059.004Unix ShellSub-technique

Sea Turtle used shell scripts for post-exploitation execution in victim environments.[3][4]

EnterpriseT1505.003Web ShellSub-technique

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.[3][4]

EnterpriseT1078Valid Accounts

Sea Turtle used compromised credentials to maintain long-term access to victim environments.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

Sea Turtle connected over TCP using HTTP to establish command and control channels.[4]

EnterpriseT1199Trusted Relationship

Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.[1]

EnterpriseT1557Adversary-in-the-Middle

Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture.[1][2]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S1163: SnappyTCP

SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims. SnappyTCP appears to be based on a public GitHub project that has since been removed from the code-sharing site. SnappyTCP includes a simple reverse TCP shell for Linux and Unix environments with basic command and control capabilities.[1]

Linux
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
77a97b048f3a1b49...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle77a97b048f3a…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  2. [2]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  3. [3]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  4. [4]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  5. [5]
    Cosmic Wolf

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  6. [6]
    Cosmic Wolf

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  7. [7]
    Cosmic Wolf

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  8. [8]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  9. [9]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  10. [10]
    Marbled Dust

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  11. [11]
    Marbled Dust

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  12. [12]
    Marbled Dust

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  13. [13]
    Microsoft Digital Defense 2021

    Microsoft. (2021, October). Microsoft Digital Defense Report. Retrieved November 20, 2024.

    Open source URL
  14. [14]
    Microsoft Digital Defense 2021

    Microsoft. (2021, October). Microsoft Digital Defense Report. Retrieved November 20, 2024.

    Open source URL
  15. [15]
    Microsoft Digital Defense 2021

    Microsoft. (2021, October). Microsoft Digital Defense Report. Retrieved November 20, 2024.

    Open source URL
  16. [16]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  17. [17]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  18. [18]
    SILICON

    (Citation: Microsoft Digital Defense 2021)(Citation: Hunt Sea Turtle 2024)

  19. [19]
    SILICON

    (Citation: Microsoft Digital Defense 2021)(Citation: Hunt Sea Turtle 2024)

  20. [20]
    SILICON

    (Citation: Microsoft Digital Defense 2021)(Citation: Hunt Sea Turtle 2024)

  21. [21]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  22. [22]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  23. [23]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  24. [24]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  25. [25]
    Teal Kurma

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  26. [26]
    Teal Kurma

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  27. [27]
    Teal Kurma

    (Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)

  28. [28]
    mitre-attackG1041
    Open source URL
  29. [29]
    mitre-attackG1041
    Open source URL
  30. [30]
    mitre-attackG1041
    Open source URL
  31. [31]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  32. [32]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  33. [33]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  34. [34]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  35. [35]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  36. [36]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  37. [37]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  38. [38]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  39. [39]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  40. [40]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  41. [41]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  42. [42]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  43. [43]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  44. [44]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  45. [45]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  46. [46]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  47. [47]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  48. [48]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  49. [49]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  50. [50]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  51. [51]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  52. [52]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  53. [53]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  54. [54]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  55. [55]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  56. [56]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  57. [57]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  58. [58]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  59. [59]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  60. [60]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  61. [61]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  62. [62]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  63. [63]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  64. [64]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  65. [65]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  66. [66]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  67. [67]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  68. [68]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  69. [69]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  70. [70]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  71. [71]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  72. [72]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  73. [73]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  74. [74]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  75. [75]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  76. [76]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  77. [77]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  78. [78]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  79. [79]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  80. [80]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  81. [81]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  82. [82]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  83. [83]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  84. [84]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  85. [85]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  86. [86]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  87. [87]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  88. [88]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  89. [89]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  90. [90]
    PWC Sea Turtle 2023

    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

    Open source URL
  91. [91]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  92. [92]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  93. [93]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  94. [94]
    Talos Sea Turtle 2019

    Cisco Talos. (2019, April 17). Sea Turtle: DNS Hijacking Abuses Trust In Core Internet Service. Retrieved November 20, 2024.

    Open source URL
  95. [95]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.