Sea Turtle is a Türkiye-based, state-supported cyberespionage threat actor aligned with Turkish strategic interests. Also known as SILICON, Teal Kurma, Marbled Dust, Cosmic Wolf, and UNC1326, it has targeted government entities, telecommunications and media organizations, internet service providers, IT and security service providers, energy organizations, think tanks, NGOs, airports, and Kurdish-affiliated entities across Europe, the Middle East, and North Africa. Its operations focus on intelligence collection, including politically sensitive information concerning minority groups and perceived political dissidents. Sea Turtle became prominent for DNS-hijacking campaigns conducted from 2017 through 2019. These operations altered victim name-server records, used actor-controlled name servers and impersonated TLS certificates, and supported adversary-in-the-middle interception of webmail and other internet traffic to harvest credentials. The group was linked to compromise of infrastructure associated with Greece’s country-code top-level-domain registry, which was used to facilitate further targeting of Greek government entities. More recent activity has included compromise of web-hosting environments through SSH access to cPanel accounts using valid credentials of unknown provenance. Sea Turtle has used Linux and Unix reverse shells, including SnappyTCP, to execute commands and maintain remote access; downloaded and locally compiled source code using GCC; collected email archives; and exfiltrated data through TCP and HTTP channels. The actor has also used anti-forensic measures, including clearing shell and database histories and overwriting Linux logs. Sea Turtle has demonstrated supply-chain and island-hopping targeting opportunities against exposed service-provider infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
19 CVEs this actor has used in observed campaigns. 19 of them exploited in the wild.
Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847...
Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228...
Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847...
Since April 2024, the threat actor Marbled Dust (aka Sea Turtle, Teal Kurma, Marbled Dust, SILICON and Cosmic Wolf) has exploited a zero-day flaw (CVE-2025-27920) in Output Messenger... The vulnerability CVE-2025-27920 is a directory traversal vulnerability... impacts Output Messenger versions before 2.0.63.
Talos believes that the threat actors have exploited multiple known CVEs... CVE-2009-1151: PHP code injection vulnerability affecting phpMyAdmin
14 more CVEs tied to this actor tracked in Mallory.
120 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an ATT&CK-associated group for this detection technique; no activity by the group is described in the content.
Referenced solely as an ATT&CK-associated group for Windows built-in account renaming/local-account abuse; no campaign or activity is described.
Listed only in detection annotation metadata.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.