Overview 51 indicators
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.
| domain | 35 | G1041-domain.txt |
| url | 13 | G1041.json |
| url_path | 2 | G1041.json |
| ipv4 | 1 | G1041.json |
Techniques 27 ATT&CK
Open in ATT&CK Navigator → or download the layer (27 techniques, layer 4.5)
- T1027.004 Compile After Delivery
- T1059.004 Unix Shell
- T1071.001 Web Protocols
- T1074.002 Remote Data Staging
- T1078 Valid Accounts
- T1078.003 Local Accounts
- T1114.001 Local Email Collection
- T1133 External Remote Services
- T1190 Exploit Public-Facing Application
- T1199 Trusted Relationship
- T1203 Exploitation for Client Execution
- T1213.006 Databases
- T1505.003 Web Shell
- T1557 Adversary-in-the-Middle
- T1560.001 Archive via Utility
- T1564.011 Ignore Process Interrupts
- T1566 Phishing
- T1583 Acquire Infrastructure
- T1583.001 Domains
- T1583.002 DNS Server
- T1583.003 Virtual Private Server
- T1584.002 DNS Server
- T1588.002 Tool
- T1588.004 Digital Certificates
- T1608.003 Install Digital Certificate
- T1685.006 Clear Linux or Mac System Logs
- T1690 Prevent Command History Logging
Software 1
Principal sources 7 reports
Ranked by how many of this actor's indicators each report brought in.
- 26pwc.com/gx/en/issues/cybersecurity/cyber-threat…
- 26blog.talosintelligence.com/seaturtle
- 17blog.strikeready.com/blog/pivoting-through-a-sea-of-indicato…
- 17otx.alienvault.com/pulse/65a0740fefe93d8593b812af
- 5huntandhackett.com/blog/turkish-espionage-campaigns
- 2microsoft.com/en-us/security/blog/2025/05/12/marbled-…
- 1virustotal.com/gui/file/d7164daf135404a0f0851ffe126a0a…
Timeline 51 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
microsoft.com/en-us/security/blog/2025/05/12/marbled-…
api.wordinfos.com wordinfos.com -
blog.strikeready.com/blog/pivoting-through-a-sea-of-indicato… · otx.alienvault.com/pulse/65a0740fefe93d8593b812af
23be.xtechsupport.org ai-connector.goldchekin.com ai-connector.splendor.org ai-connector.splendos.org alarabiyaa.online caglayandergisi.net cn.sslname.com exp-al-marsad.co infohaber.net loading-website.net netssh.net nuceciwan.news serverssl.net solhaber.info solhaber.news update.qnetau.net xtechsupport.org -
huntandhackett.com/blog/turkish-espionage-campaigns
domain boord.info domain forward.boord.info url http://193.34.167.245 url_path /c00n/connn.c url_path /c00n/socat -
virustotal.com/gui/file/d7164daf135404a0f0851ffe126a0a…
62.115.255.163:61265 -
pwc.com/gx/en/issues/cybersecurity/cyber-threat… · blog.talosintelligence.com/seaturtle
domain al-marsad.co domain alhurra.online domain anfturkce.news domain aws.systemctl.network domain dhcp.systemctl.network domain eth0.secrsys.net domain lo0.systemctl.network domain nmcbcd.live domain querryfiles.com domain secrsys.net domain systemctl.network domain ud.ybcd.tech domain upt.mcsoft.org domain ybcd.tech url http://108.61.103.186 url http://146.190.28.83 url http://168.100.10.187 url http://168.100.8.245 url http://168.100.9.203 url http://199.247.29.25 url http://31.13.195.52 url http://31.214.157.230 url http://45.80.148.172 url http://88.119.171.248 url http://93.115.22.212 url http://95.179.176.250
Further reading 10
- attack.mitre.org/groups/G1041
- blog.talosintelligence.com/sea-turtle-keeps-on-swimming
- blog.talosintelligence.com/seaturtle
- query.prod.cms.rt.microsoft.com/cms/api/am/binary/RWMFIi?id=101738
- huntandhackett.com/blog/turkish-espionage-campaigns
- pwc.com/gx/en/issues/cybersecurity/cyber-threat…
- otx.alienvault.com/pulse/65a0740fefe93d8593b812af
- blog.strikeready.com/blog/pivoting-through-a-sea-of-indicato…
- virustotal.com/gui/file/d7164daf135404a0f0851ffe126a0a…
- microsoft.com/en-us/security/blog/2025/05/12/marbled-…