[Sea Turtle](https://attack.mitre.org/groups/G1041) staged collected email archives in the public web directory of a website that was accessible from the internet.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) used the tool Adminer to remotely logon to the MySQL service of victim machines.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) used the tar utility to create a local archive of email data on a victim system.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) connected over TCP using HTTP to establish command and control channels.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) modified DNS records at service providers to redirect traffic from legitimate resources to [Sea Turtle](https://attack.mitre.org/groups/G1041)-controlled servers to enable adversary-in-the-middle attacks for credential capture.(Citation: Talos Sea
[Sea Turtle](https://attack.mitre.org/groups/G1041) has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution.(Citation: PWC Sea Turtle 2023)
[Sea Turtle](https://attack.mitre.org/groups/G1041) targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.(Citation: Talos Sea
[Sea Turtle](https://attack.mitre.org/groups/G1041) gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns.(Citation: Talos Sea Turtle 2019)(Citation: PWC Sea Turtle 2023)
[Sea Turtle](https://attack.mitre.org/groups/G1041) has used external-facing SSH to achieve initial access to the IT environments of victim organizations.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials.(Citation: Talos Sea Turtle 2019_2)(Citation: Talos Sea Turtle 2019)
[Sea Turtle](https://attack.mitre.org/groups/G1041) captured legitimate SSL certificates from victim organizations and installed these on [Sea Turtle](https://attack.mitre.org/groups/G1041)-controlled infrastructure to enable subsequent adversary-in-the-middle operations.(Citation: Talos Sea Turtle
[Sea Turtle](https://attack.mitre.org/groups/G1041) modified Name Server (NS) items to refer to [Sea Turtle](https://attack.mitre.org/groups/G1041)-controlled DNS servers to provide responses for all DNS lookups.(Citation: Talos Sea Turtle 2019)(Citation: Talos Sea Turtle 2019_2)
[Sea Turtle](https://attack.mitre.org/groups/G1041) created new certificates using a technique called the actors performed "certificate impersonation," a technique in which [Sea Turtle](https://attack.mitre.org/groups/G1041) obtained a certificate authority-signed X.509 certificate from another prov
[Sea Turtle](https://attack.mitre.org/groups/G1041) registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers.(Citation: Talos Sea Turtle 2019_2)(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) executed [SnappyTCP](https://attack.mitre.org/software/S1163) using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.(Citation: Hunt Sea Turtle 2024)
[Sea Turtle](https://attack.mitre.org/groups/G1041) used compromised credentials to maintain long-term access to victim environments.(Citation: Talos Sea Turtle 2019)
Associated software
1 linked · 1 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 1
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Sea Turtle's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 11 techniques
Advanced Anti-Phishing T1566partialAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1213minimalConditional AccessT1074minimalConditional AccessT1074.002minimalConditional AccessT1078minimalConditional AccessT1213minimalIdentity Secure ScoreT1078minimalIdentity Secure ScoreT1078.003minimalMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1566partialPrivileged Identity ManagementT1078minimalPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1059minimalRole Based Access ControlT1078minimalRole Based Access ControlT1199partialRole Based Access ControlT1213partialAntimalwareT1027significantAntimalwareT1059significantAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significantMail Flow RulesT1114significantAudit SolutionsT1078partialAudit SolutionsT1114partialAudit SolutionsT1213partial
detect · 10 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1078significantApp GovernanceT1199significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1114significantAdvanced Threat HuntingT1199significantAdvanced Threat HuntingT1566significantDefender for Cloud AppsT1071minimalDefender for Cloud AppsT1078partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1213minimalMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for Identity
respond · 7 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1114significantAutomated Investigation and ResponseT1566significantIncident ResponseT1059minimalIncident ResponseT1078minimalIncident ResponseT1213minimalIncident ResponseT1564minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1213significantQuarantine PoliciesT1566significantSafe AttachmentsT1566significantATT&CK Simulation Training
Countermeasures · D3FEND
Defensive techniques that counter Sea Turtle's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.