Sea Turtle is a Turkey-linked state-supported espionage threat actor known for DNS hijacking, adversary-in-the-middle credential collection, and Linux-focused post-compromise activity. Widely used aliases include SILICON, Teal Kurma, Marbled Dust, and Cosmic Wolf; Microsoft has associated the actor with the Türkiye-attributed Dust naming family. The group has been active since at least 2017 and is assessed to pursue intelligence collection aligned with Turkish strategic interests. Sea Turtle became particularly notable for large-scale DNS hijacking operations against public and private organizations. Its operations have included modifying registrar or name server settings, redirecting victim traffic to actor-controlled infrastructure, impersonating legitimate services with fraudulent or impersonating certificates, and harvesting credentials through man-in-the-middle workflows. The actor has also operated dedicated adversary-in-the-middle servers and targeted internet infrastructure providers and registries to enable downstream compromises of additional victims. Targeting has centered on government organizations, telecommunications providers, internet service providers, IT service providers, energy companies, think tanks, NGOs, media organizations, airports, and Kurdish political or affiliated entities. Reported victim geography spans Europe, the Middle East, and North Africa, with specific activity documented against organizations in Greece, the Netherlands, and Syria. The actor has also shown interest in domestic Turkish political issues and information on minority groups and dissidents. Beyond DNS hijacking, Sea Turtle has conducted direct intrusions into Linux-hosted environments using compromised cPanel accounts and SSH access, followed by shell-based post-exploitation. Observed tradecraft includes use of reverse shells, HTTP-based command and control, deployment of Adminer, collection of email archives for likely exfiltration, and anti-forensic measures such as clearing shell history and overwriting logs. Sea Turtle has also been observed downloading source code to victim systems and compiling it locally with GCC, reflecting an effort to evade static detection and blend into legitimate administrative activity. Additional reported behaviors include persistence through boot or logon initialization mechanisms and use of privileged container execution in Linux environments. Overall, Sea Turtle is best characterized as a Turkish espionage actor specializing in credential theft and surveillance-enabling access operations, combining infrastructure compromise, DNS manipulation, adversary-in-the-middle collection, and hands-on-keyboard intrusion techniques to support strategic intelligence gathering.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
19 CVEs this actor has used in observed campaigns. 19 of them exploited in the wild.
Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847...
Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228...
Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847...
Since April 2024, the threat actor Marbled Dust (aka Sea Turtle, Teal Kurma, Marbled Dust, SILICON and Cosmic Wolf) has exploited a zero-day flaw (CVE-2025-27920) in Output Messenger... The vulnerability CVE-2025-27920 is a directory traversal vulnerability... impacts Output Messenger versions before 2.0.63.
Talos believes that the threat actors have exploited multiple known CVEs... CVE-2009-1151: PHP code injection vulnerability affecting phpMyAdmin
14 more CVEs tied to this actor tracked in Mallory.
120 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only in detection annotation metadata.
Named only in the analytic annotation list; no specific operation or malware usage is discussed in this content.
Listed as an example threat actor associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Listed as an annotated threat actor associated with the detection, but no campaign-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.