created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Sea Turtle
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1041 |
| Aliases | Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON |
| Attribution | Turkey |
| Class | state |
| Active since | 2017 (per ATT&CK description) |
| ATT&CK entry created | 2024-11-20 |
| Techniques mapped | 28 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1027.004 |
Compile After Delivery |
T1059.004 |
Unix Shell |
T1071.001 |
Web Protocols |
T1074.002 |
Remote Data Staging |
T1078 |
Valid Accounts |
T1078.003 |
Local Accounts |
T1114.001 |
Local Email Collection |
T1133 |
External Remote Services |
T1190 |
Exploit Public-Facing Application |
T1199 |
Trusted Relationship |
T1203 |
Exploitation for Client Execution |
T1213.006 |
Databases |
(First 12 of 28 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — Turkey-linked actor, same attribution class
- Apt28 — Turkey-linked actor, same attribution class
- Apt29 — Turkey-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1041 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.