Sea Turtle (MITRE G1041; Microsoft 'Marbled Dust') is a Turkiye-aligned espionage group notorious for DNS hijacking and service-provider compromise, targeting government, telecom and IT organizations across the Middle East, Europe and beyond.
Sea Turtle was first exposed by Cisco Talos in 2019 for an aggressive DNS-hijacking campaign that compromised registrars and DNS providers to redirect victims and harvest credentials via spoofed login portals. MITRE tracks it as G1041, with aliases including Teal Kurma (PwC), Marbled Dust (Microsoft), Cosmic Wolf and SILICON; activity dates to at least 2017.
The group's hallmark is abusing trust in core internet infrastructure: DNS record manipulation at ccTLD and provider level, plus typo-squatted domains and credential interception, to reach downstream targets. More recent operations pair this with conventional intrusion tooling, including reverse-shell and Golang backdoors and web shells.
MENA relevance is central to Sea Turtle's mission. Its DNS-hijacking wave (2018-2020) intercepted government IT traffic in Greece, Cyprus and Iraq, and its targeting consistently aligns with Turkish strategic interests, especially Kurdish entities. In May 2025, Microsoft reported Marbled Dust exploiting an Output Messenger zero-day (CVE-2025-27920) to deploy Golang backdoors against Kurdish military-linked targets in Iraq, a campaign ongoing since at least April 2024. The group also resurfaced against Dutch IT and telecom firms (reported 2024).
Confidence in the activity is high given multi-vendor corroboration (Talos, PwC, Microsoft, Hunt.io); the Turkiye-state alignment is a high-confidence assessment based on consistent victimology and interest alignment, though not an official government attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1213.006 ↗ | Data from Information Repositories: Databases | collection | used the tool Adminer to remotely logon to the MySQL service |
| T1074.002 ↗ | Data Staged: Remote Data Staging | collection | staged collected email archives in the public web directory |
| T1557 ↗ | Adversary-in-the-Middle | collection | modified DNS records at service providers to redirect traffic to Sea Turtle servers |
| T1114.001 ↗ | Email Collection: Local Email Collection | collection | collected email archives from victim environments |
| T1560.001 ↗ | Archive Collected Data: Archive via Utility | collection | used the tar utility to create a local archive of email data |
| T1071.001 ↗ | Application Layer Protocol: Web Protocols | command and control | connected over TCP using HTTP to establish command and control channels |
| T1078 ↗ | Valid Accounts | defense evasion | used compromised credentials to maintain long-term access |
| T1078.003 ↗ | Valid Accounts: Local Accounts | defense evasion | compromised cPanel accounts in victim environments |
| T1564.011 ↗ | Hide Artifacts: Ignore Process Interrupts | defense evasion | executed SnappyTCP using the tool NoHup to maintain persistence |
| T1027.004 ↗ | Obfuscated Files or Information: Compile After Delivery | defense evasion | downloaded source code files from remote addresses then compiled locally via GCC |
| T1690 ↗ | Prevent Command History Logging | defense evasion | unset the Bash and MySQL history files on victim systems |
| T1685.006 ↗ | Disable or Modify Tools: Clear Linux or Mac System Logs | defense evasion | overwritten Linux system logs and unsets the Bash history file |
| T1203 ↗ | Exploitation for Client Execution | execution | used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, CVE-2022-0847 |
| T1059.004 ↗ | Command and Scripting Interpreter: Unix Shell | execution | used shell scripts for post-exploitation execution |
| T1566 ↗ | Phishing | initial access | used spear phishing to gain initial access to victims |
| T1133 ↗ | External Remote Services | initial access | used external-facing SSH to achieve initial access |
| T1190 ↗ | Exploit Public-Facing Application | initial access | gained access to victim environments by exploiting multiple known vulnerabilities |
| T1199 ↗ | Trusted Relationship | initial access | targeted third-party entities in trusted relationships including DNS registrars and ISPs |
| T1505.003 ↗ | Server Software Component: Web Shell | persistence | deployed the SnappyTCP web shell during intrusion operations |
| T1588.004 ↗ | Obtain Capabilities: Digital Certificates | resource development | obtained certificate authority-signed X.509 certificate impersonating target domains |
| T1583.001 ↗ | Acquire Infrastructure: Domains | resource development | registered domains for authoritative name servers used in DNS hijacking |
| T1583.002 ↗ | Acquire Infrastructure: DNS Server | resource development | built adversary-in-the-middle DNS servers to impersonate legitimate services |
| T1583.003 ↗ | Acquire Infrastructure: Virtual Private Server | resource development | created adversary-in-the-middle servers to impersonate legitimate services |
| T1584.002 ↗ | Compromise Infrastructure: DNS Server | resource development | modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers |
| T1588.002 ↗ | Obtain Capabilities: Tool | resource development | used tools such as Adminer during intrusions |
| T1583 ↗ | Acquire Infrastructure | resource development | accessed victim networks from VPN service provider networks |
| T1608.003 ↗ | Stage Capabilities: Install Digital Certificate | resource development | captured legitimate SSL certificates from victim organizations for MITM operations |