◇ SIGN IN
← all actors
apt

Sea Turtle

activehigh confidence
APT / State-sponsored
Teal KurmaMarbled DustCosmic WolfSILICONUNC1326
Attribution
Turkiye-aligned / Turkish-state-nexus espionage actor (assessed)
Origin
Turkey
First seen
2019
Last active
2025
Motivation
Espionage
Confidence
high
MENA targeting
Turkey, Iran, Egypt, Cyprus, Greece, broader MENA
Sectors
Government/foreign ministries, military, intelligence, energy, telecom, ISPs
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Turkey, Iran, Egypt (Government/foreign ministries, military, intelligence sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Sea Turtle (MITRE G1041; Microsoft 'Marbled Dust') is a Turkiye-aligned espionage group notorious for DNS hijacking and service-provider compromise, targeting government, telecom and IT organizations across the Middle East, Europe and beyond.

History

Sea Turtle was first exposed by Cisco Talos in 2019 for an aggressive DNS-hijacking campaign that compromised registrars and DNS providers to redirect victims and harvest credentials via spoofed login portals. MITRE tracks it as G1041, with aliases including Teal Kurma (PwC), Marbled Dust (Microsoft), Cosmic Wolf and SILICON; activity dates to at least 2017.

The group's hallmark is abusing trust in core internet infrastructure: DNS record manipulation at ccTLD and provider level, plus typo-squatted domains and credential interception, to reach downstream targets. More recent operations pair this with conventional intrusion tooling, including reverse-shell and Golang backdoors and web shells.

MENA relevance is central to Sea Turtle's mission. Its DNS-hijacking wave (2018-2020) intercepted government IT traffic in Greece, Cyprus and Iraq, and its targeting consistently aligns with Turkish strategic interests, especially Kurdish entities. In May 2025, Microsoft reported Marbled Dust exploiting an Output Messenger zero-day (CVE-2025-27920) to deploy Golang backdoors against Kurdish military-linked targets in Iraq, a campaign ongoing since at least April 2024. The group also resurfaced against Dutch IT and telecom firms (reported 2024).

Confidence in the activity is high given multi-vendor corroboration (Talos, PwC, Microsoft, Hunt.io); the Turkiye-state alignment is a high-confidence assessment based on consistent victimology and interest alignment, though not an official government attribution.

Notable campaigns

2019
DNS hijacking operations
Talos exposed compromise of registrars/DNS providers to redirect and harvest credentials from government and infrastructure targets in the Middle East and North Africa.
2024
Dutch IT/telecom espionage
Sea Turtle resurfaced targeting Dutch IT, telecom and Kurdish-diaspora-linked organizations for intelligence collection.
2025
Output Messenger zero-day (Marbled Dust)
Microsoft reported exploitation of CVE-2025-27920 to drop Golang backdoors on servers tied to Kurdish military operations in Iraq.

Observed ATT&CK techniques · 27

TechniqueNameTacticObserved use
T1213.006Data from Information Repositories: Databasescollectionused the tool Adminer to remotely logon to the MySQL service
T1074.002Data Staged: Remote Data Stagingcollectionstaged collected email archives in the public web directory
T1557Adversary-in-the-Middlecollectionmodified DNS records at service providers to redirect traffic to Sea Turtle servers
T1114.001Email Collection: Local Email Collectioncollectioncollected email archives from victim environments
T1560.001Archive Collected Data: Archive via Utilitycollectionused the tar utility to create a local archive of email data
T1071.001Application Layer Protocol: Web Protocolscommand and controlconnected over TCP using HTTP to establish command and control channels
T1078Valid Accountsdefense evasionused compromised credentials to maintain long-term access
T1078.003Valid Accounts: Local Accountsdefense evasioncompromised cPanel accounts in victim environments
T1564.011Hide Artifacts: Ignore Process Interruptsdefense evasionexecuted SnappyTCP using the tool NoHup to maintain persistence
T1027.004Obfuscated Files or Information: Compile After Deliverydefense evasiondownloaded source code files from remote addresses then compiled locally via GCC
T1690Prevent Command History Loggingdefense evasionunset the Bash and MySQL history files on victim systems
T1685.006Disable or Modify Tools: Clear Linux or Mac System Logsdefense evasionoverwritten Linux system logs and unsets the Bash history file
T1203Exploitation for Client Executionexecutionused exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, CVE-2022-0847
T1059.004Command and Scripting Interpreter: Unix Shellexecutionused shell scripts for post-exploitation execution
T1566Phishinginitial accessused spear phishing to gain initial access to victims
T1133External Remote Servicesinitial accessused external-facing SSH to achieve initial access
T1190Exploit Public-Facing Applicationinitial accessgained access to victim environments by exploiting multiple known vulnerabilities
T1199Trusted Relationshipinitial accesstargeted third-party entities in trusted relationships including DNS registrars and ISPs
T1505.003Server Software Component: Web Shellpersistencedeployed the SnappyTCP web shell during intrusion operations
T1588.004Obtain Capabilities: Digital Certificatesresource developmentobtained certificate authority-signed X.509 certificate impersonating target domains
T1583.001Acquire Infrastructure: Domainsresource developmentregistered domains for authoritative name servers used in DNS hijacking
T1583.002Acquire Infrastructure: DNS Serverresource developmentbuilt adversary-in-the-middle DNS servers to impersonate legitimate services
T1583.003Acquire Infrastructure: Virtual Private Serverresource developmentcreated adversary-in-the-middle servers to impersonate legitimate services
T1584.002Compromise Infrastructure: DNS Serverresource developmentmodified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers
T1588.002Obtain Capabilities: Toolresource developmentused tools such as Adminer during intrusions
T1583Acquire Infrastructureresource developmentaccessed victim networks from VPN service provider networks
T1608.003Stage Capabilities: Install Digital Certificateresource developmentcaptured legitimate SSL certificates from victim organizations for MITM operations