Sea Turtle
COSMIC WOLFMarbled DustSILICONTeal KurmaUNC1326
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the… Source: MISP
Attributed country: TR according to MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 18 Sep 2026 · last seen on 18 Sep 2026
News
MITRE ATT&CK techniques
Resource Development
T1583Acquire InfrastructureT1583.001DomainsT1583.002DNS ServerT1583.003Virtual Private ServerT1584.002DNS ServerT1588.002Tool 7 Sigma rulesT1588.004Digital CertificatesT1608.003Install Digital Certificate 1 Sigma rules
Initial Access
T1078Valid Accounts 82 Sigma rulesT1078.003Local Accounts 4 Sigma rulesT1133External Remote Services 17 Sigma rulesT1190Exploit Public-Facing Application 40 Sigma rulesT1199Trusted Relationship 1 Sigma rulesT1566Phishing 28 Sigma rules
Execution
Persistence
Credential Access
Collection
T1074.002Remote Data StagingT1114.001Local Email Collection 1 Sigma rulesT1213.006DatabasesT1560.001Archive via Utility 10 Sigma rules
Command and Control
Stealth
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗