socat is referenced in the reporting as tooling Hunt & Hackett believes Sea Turtle used, possibly in modified form, to establish command-and-control channels. In the observed Netherlands-focused Sea Turtle espionage campaigns between 2021 and 2023, the actor targeted telecommunications, media, ISPs, IT service providers, and Kurdish-affiliated websites. The report attributes the activity to the Turkey-aligned espionage actor Sea Turtle, also known as SILICON, Teal Kurma, Marbled Dust, and Cosmic Wolf. The specific mention states that the C2 channel was set up with what Hunt & Hackett believes is a form of socat, as detected by the THOR APT Scanner on VirusTotal. The content does not provide additional high-confidence technical details on the socat sample itself, infection vector, persistence, or unique indicators specific to this tooling beyond its suspected use for C2 in Sea Turtle operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The command-and-control (C&C) channel is setup with what Hunt & Hackett believes is a form of Socat, as detected by the THOR APT Scanner on Virustotal.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Usage of the third-party tunneling tool Twingate... Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
Command and Control T1071.001 T1095 Sea Turtle configured SnappyTCP to establish a command-and-control channel to the domain name forward.boord[.]info on port 443 using the protocols TCP and HTTP.
The infection starts with the delivery of a downloader that downloads multiple payloads... Once the attackers achieve initial compromise, the downloader downloads three files... A Pyrome python backdoor is downloaded by this shellcode. This will also download socat and xmrig miner, and finally xmrig miner downloads another RAT named Quasar.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.