TR

Sea TurtleSea Turtle

Also known as: COSMIC WOLF · Marbled Dust · SILICON · Teal Kurma · UNC1326 · Sea Turtle

Origin
TR
Known aliases
6

Profile

This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has the potential to undermine the trust users have on the internet. That trust and the stability of the DNS system as a whole drives the global economy. Responsible nations should avoid targeting this system, work together to establish an accepted global norm that this system and the organizations that control it are off-limits, and cooperate in pursuing those actors who act irresponsibly by targeting this system.

Aliases· 6

COSMIC WOLFMarbled DustSILICONTeal KurmaUNC1326Sea Turtle

Known victims· 1

  • Germany

References

  1. https://blog.talosintelligence.com/2019/04/seaturtle.html
  2. https://blog.talosintelligence.com/sea-turtle-keeps-on-swimming
  3. https://www.reuters.com/article/us-cyber-attack-hijack-exclusive/exclusive-hackers-acting-in-turkeys-interests-believed-to-be-behind-recent-cyberattacks-sources-idUSKBN1ZQ10X
  4. https://icann.zoom.us/recording/play/AhQB4AQyjCuEJGz2wQQans0Xqkz3su8swGLQoORJhdECw9ttz0TbuyzBlue85gIY
  5. https://community.icann.org/download/attachments/109483867/Cybersecurity%20and%20the%20ICANN%20Ecosystem.pdf
  6. https://www.pwc.co.uk/cyber-security/assets/cyber-threats-2019-retrospect.pdf
  7. https://www.pwc.co.uk/cyber-security/pdf/pwc-cyber-threats-2020-a-year-in-retrospect.pdf
  8. https://www.domaintools.com/resources/blog/finding-additional-indicators-with-passive-dns-within-domaintools-iris

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Tortoiseshell
Actor
DNSpionage
Actor
MuddyWater
Actor
UNC1549
Actor
QUILTED TIGER
Actor
WildNeutron
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.