logo

Turkish hackers Sea Turtle expand attacks to Dutch ISPs, telcos

ID: cbcf1450-18d7-5e63-bd66-f29f60f0ec58

STIX ID: report--cbcf1450-18d7-5e63-bd66-f29f60f0ec58

Feed Name: Bleeping Computer

Threat Score
76/100

Date Published: 2024-01-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Hunt & Hackett observed Sea Turtle (Turkish state–linked) espionage activity in the Netherlands (2021–2023) targeting telecommunications, media, ISPs and Kurdish websites. Operators used compromised cPanel accounts and SSH for access, deployed a persistent reverse shell (SnappyTCP) and Adminer for data access, erased logs and history for evasion, and exfiltrated email archives via public web directories; no lateral movement or credential theft post-compromise was observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.