Uptime Hamster: 10d 10h 55mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Sea Turtle

Sea Turtle

1 incidentes 0 paises 0 sectores apt TR Ultimo: 2026-05-25
Aliases: COSMIC WOLF, Marbled Dust, SILICON, Teal Kurma, UNC1326, snappytcp, DNS hijacking, vinculado a múltiples vulnerabilidades cibernéticas
Ver en IntelTracker → APTTrail →
Sea Turtle is a state-affiliated advanced persistent threat (APT) group believed to operate in alignment with Turkish interests, active since at least 2017. The group's primary motivation is state-sponsored espionage, focused on acquiring economic and political intelligence through information theft and surveillance. Sea Turtle is distinguished by its historical and continued use of DNS hijacking to redirect internet traffic and steal credentials, a tactic that has evolved to include targeting cloud environments and exploiting supply chain vulnerabilities to reach ultimate targets. Initially emerging through DNS hijacking campaigns between 2017 and 2019, the group has since evolved its tactics to include exploiting known vulnerabilities, using custom Linux/Unix implants, and focusing on cloud-based intrusions by 2023. This group operates under several aliases, including Teal Kurma, Marbled Dust, SILICON, Cosmic Wolf, and UNC1326.

Aliases del actor

COSMIC WOLFMarbled DustSILICONTeal KurmaUNC1326snappytcpDNS hijackingvinculado a múltiples vulnerabilidades cibernéticas

Actores similares

apt-marbleddustactor · 1sea-turtleactor · 1direwolfransomware · 18stealthmole_intactor · 8apt-bloodywolfactor · 1apt-cosmicdukeactor · 1apt-dnspionageactor · 1rare-werewolfactor · 1apt-seafloweractor · 1apt-stealthfalconactor · 1
Motivacion