Sea Turtle
G10412 reportsaliases · Sea Turtle · Teal Kurma · Marbled Dust · Cosmic Wolf · SILICON
2
Reports
12
Techniques
8
Tactics
3
Countries
31%
Hunt coverage
5
Aliases
Analyst assessment — key judgments
- Signature techniques: T1590.005 (IP Addresses), T1588.006 (Vulnerabilities), T1552.004 (Private Keys).
- Primary targeting: RU, KP, US.
- Activity declining: 0 report(s) in last 30d vs 1 prior (-100%).
- Hunt coverage 31% of 52 observed techniques (36 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
DecliningLast 30d: 0 vs 1 prior (-100%)· first reported 2025-09-10 · last 2026-08-03
0
7d
0
30d
1
90d
2
All
0.1
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
Dropped (90d+)
T1590.005T1588.006T1552.004T1589.001AML.T0016.002Targeting lost
KPRUOverview
Analyst triage
Intelligence summary
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.(Citation: Talos Sea Turtle 2019)(Citation: Talos Sea Turtle 2019_2)(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1590.005 · IP Addressesconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1552.004 · Private Keysconf 601
- T1589.001 · Credentialsconf 601
- AML.T0016.002 · Generative AIconf 601
- T1053.005 · Scheduled Taskconf 601
- T1047 · Windows Management Instrumentationconf 601
- T1033 · System Owner/User Discoveryconf 601
- T1543 · Create or Modify System Processconf 601
- T1069 · Permission Groups Discoveryconf 601
- T1071.004 · DNSconf 601
- T1547 · Boot or Logon Autostart Executionconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|