Skip to content
Cisco Talos Reports Ongoing Sea Turtle DNS Hijacking Campaign

Cisco Talos Reports Ongoing Sea Turtle DNS Hijacking Campaign

First seen 8 Oct 2026, 10:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 11:32 UTC
  • •Sea Turtle campaign targets DNS systems of national security organizations.
  • •At least 40 organizations across 13 countries have been compromised since 2017.
  • •New DNS hijacking techniques have emerged, increasing the threat level.

Cisco Talos has identified a persistent cyber threat campaign named 'Sea Turtle' that manipulates DNS systems, primarily targeting national security organizations in the Middle East and North Africa. The campaign, which began as early as January 2017, has compromised at least 40 organizations across 13 countries. Recent findings indicate that the actors behind Sea Turtle have regrouped and are employing a new DNS hijacking technique, compromising name server records to respond to DNS requests with falsified A records. This new technique has only been observed in a few targeted operations, including a country code top-level domain (ccTLD) registry. The ongoing threat underscores the potential for broader attacks on the global DNS system, which could undermine internet trust and stability. Cisco Talos emphasizes the need for responsible nations to establish norms protecting the DNS system from such attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2009-03-26
CVE-2009-1151 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2014-09-24
CVE-2014-6271 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-03-17
CVE-2017-3881 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-07-17
CVE-2017-6736 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-10-03
CVE-2017-12617 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-03-29
CVE-2018-7600 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-06-07
CVE-2018-0296 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-08
Cisco Talos publishes Sea Turtle report
Talos publishes findings on the Sea Turtle campaign, detailing its ongoing operations and impact.
blog.talosintelligence.com
Recent
Cisco Talos discovers new Sea Turtle activity
Talos reports that Sea Turtle actors have regrouped and are using new infrastructure for DNS hijacking.
blog.talosintelligence.com

More articles in this cluster (2)

Following this threat?

Track Sea Turtle and CVE-2009-1151 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What organizations are targeted?
The Sea Turtle campaign primarily targets national security organizations in the Middle East and North Africa.
What is the new technique used by Sea Turtle?
The new technique involves compromising name server records to respond to DNS requests with falsified A records.
What should organizations do to protect against this threat?
Organizations should enhance their DNS security measures and monitor for unusual DNS activity.