Turkish hackers Sea Turtle expand attacks to Dutch ISPs, telcos
ID: cbcf1450-18d7-5e63-bd66-f29f60f0ec58
STIX ID: report--cbcf1450-18d7-5e63-bd66-f29f60f0ec58
Feed Name: Bleeping Computer
Threat Score
Hunt & Hackett observed Sea Turtle (Turkish state–linked) espionage activity in the Netherlands (2021–2023) targeting telecommunications, media, ISPs and Kurdish websites. Operators used compromised cPanel accounts and SSH for access, deployed a persistent reverse shell (SnappyTCP) and Adminer for data access, erased logs and history for evasion, and exfiltrated email archives via public web directories; no lateral movement or credential theft post-compromise was observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
