Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

Sea Turtle

Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.

Attribute Detail
ATT&CK ID G1041
Aliases Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
Attribution Turkey
Class state
Active since 2017 (per ATT&CK description)
ATT&CK entry created 2024-11-20
Techniques mapped 28

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1027.004 Compile After Delivery
T1059.004 Unix Shell
T1071.001 Web Protocols
T1074.002 Remote Data Staging
T1078 Valid Accounts
T1078.003 Local Accounts
T1114.001 Local Email Collection
T1133 External Remote Services
T1190 Exploit Public-Facing Application
T1199 Trusted Relationship
T1203 Exploitation for Client Execution
T1213.006 Databases

(First 12 of 28 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Ke3Chang — Turkey-linked actor, same attribution class
  • Apt28 — Turkey-linked actor, same attribution class
  • Apt29 — Turkey-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1041 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.