Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - NEWS: State-Backed “Sea Turtle” Hacker Group Hijacking Government Website Domains For Entire Countries
News & Analysis

NEWS: State-Backed “Sea Turtle” Hacker Group Hijacking Government Website Domains For Entire Countries

ISBuzz TeamBy ISBuzz TeamApril 18, 2019Updated:July 4, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Transaction Signing Solution
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

News broke overnight on how the state-backed “Sea Turtle” hacker group is hijacking government domains for entire countries.   

Cyberspies Hijacked the Internet Domains of Entire Countries – A mysterious new group called Sea Turtle targeted 40 organizations https://t.co/BGbbPBmLkP via @WIRED #cybersecurity #cyberattacks #hacking #hackers

— Alexander von Witzleben (@AlexWitzleben) April 18, 2019

In brief, the hackers would change the target organization’s domain registration to point to their own DNS servers—the computers that perform the DNS translation of domains into IP addresses—instead of the victim’s legitimate ones. This sort of man-in-the-middle attack should be prevented by SSL certificates, but the hackers simply used spoofed certificates from Let’s Encrypt or Comodo, invalid on close inspection but still able to trick users with signs of legitimacy.   

Expert Comments:

Martin Thorpe, Enterprise Security Architect at Venafi: 

“This campaign of attacks is highly likely to have serious consequences. The impact of hijacking of the top-level domains – and the encrypted communication streams – for entire countries, including close UK and US allies such as Egypt, Turkey, Jordan and the UAE, is hard to overstate. We don’t know which communications have been intercepted, but it’s not hard to imagine the range of extremely sensitive political, military and commercial topics that could have been intercepted.   

“Crucially, Sea Turtle’s attacks were aimed at the bedrock infrastructure of the internet. Targeting the top-level domains and DNS servers provides a clean – and hard to detect – end run around even the most sophisticated end-point protection, anti-virus, intrusion detection and advanced persistent threat defences. Sea Turtle went straight to attacking the machine identities that underpin all of the traditional cyber defence technologies. The attackers then carefully used Let’s Encrypt to issue forged certificates, successfully impersonating their targets.  

“This attack shines a very bright spotlight on how we secure DNS servers and other core infrastructure. It also directly draws attention to how we secure and protect machine identities. Active monitoring of DNS and public certificates, similarly to how Venafi TrustNet operates, is now proven to be critical to enterprise and even governmental cyber defence.   

“It is also important to note that this is not an isolated case. In the past few years we’ve seen an increasing number of incidents involving certificate authorities (CAs), which have resulted in compromised websites and companies.   

“Earlier this year we released findings of the first ever academic study into the marketplace for legitimate TLS/SSL certificates on the dark web – machine identities which have an even greater level of trust – showing that hackers are now moving upstream to even higher value targets. The study, undertaken by The Center for Evidence-Based Cybersecurity at the Andrews School of Policy Studies at the University of Georgia and the University of Surrey, found a thriving marketplace for TLS certificates, with prices ranging up to $1,600.   

“It is vital that the industry wakes up to this problem or we are likely to see even more attacks of this kind with increasing regularity and severity.” 

Corin Imai, Senior Security Advisor at DomainTools: 

“DNS hijacking is a particularly dangerous attack technique due to the wide variety of malicious activity that it can facilitate. Whether the redirected traffic is used for phishing purposes, or in order to provide targeted advertisements to people using specific websites, it can be a powerful tool. The fact that these websites are associated with government and infrastructure targets, it is likely that the aim of this hijacking campaign is espionage. What’s more, this is not the first time “Sea Turtle” has been caught, and as they continue to successfully “break the trust model of the internet”.”

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}