Sea Turtle: The State-Sponsored Campaign That Hijacked DNS to Spy on Governments
How "Sea Turtle," a state-sponsored campaign disclosed by Cisco Talos in 2019, hijacked DNS through registrars, registries, and DNS providers — redirecting governments, ministries, and energy firms to attacker servers, obtaining CA-signed and other certificates for interception, and breaching a national TLD registry.
- domains
- security
- dns
- domain-security
Most cyberattacks try to break into a target. The Sea Turtle campaign did something quieter and far more dangerous: it broke into the map that tells the entire internet where the target lives.
When you type a government ministry's web address, or send email to its officials, your computer first asks the Domain Name System — DNS — to translate that human-readable name into the numeric address of the right server. Protections such as DNSSEC, TLS certificate validation, and routing security can verify parts of that path, but coverage and enforcement are uneven. Sea Turtle's operators exploited those gaps for more than two years to spy on governments across the Middle East and North Africa.
Disclosed by Cisco Talos in April 2019, Sea Turtle is one of the clearest case studies we have of DNS being weaponized as an instrument of nation-state espionage. The attackers went after the registrars, registries, and DNS providers that sit above their targets. From that vantage point they rerouted traffic, harvested credentials, and used CA-signed, stolen, or self-signed certificates on interception servers. A CA-signed certificate was legitimately issued after domain validation; it was not a forged cryptographic signature.
DNS as a target for nation-state espionage
DNS is sometimes called the phone book of the internet, but that undersells it. It's closer to the postal routing system: every email, every login, every API call begins by resolving a name. If you control the resolution, you control the destination — and you can sit invisibly in the middle of conversations that both sides believe are private and direct.
That makes DNS an almost perfect espionage target. Compromising one DNS provider can expose the traffic of every organization that depends on it. And unlike malware on an endpoint, DNS manipulation leaves the victim's own machines untouched: there's nothing to scan, nothing to quarantine. The records simply point somewhere new.
Talos was blunt about the mechanism. As their report put it, DNS hijacking occurs when the actor can illicitly modify DNS name records to point users to actor-controlled servers. Simple to describe; devastating in practice.
The Sea Turtle campaign (2017–2019)

Sea Turtle was not a smash-and-grab. Talos assessed that the ongoing operation likely began as early as January 2017 and has continued through the first quarter of 2019 — more than two years of patient, persistent operations.
Over that span, by Talos's count, at least 40 different organizations across 13 different countries were compromised during this campaign. TechCrunch summarized the reach: the group had targeted 40 government and intelligence agencies, telecom firms and internet giants in 13 countries for more than two years, with victims found across countries including Armenia, along with Egypt, Turkey, Sweden, Jordan and the United Arab Emirates.
Talos declined to publicly attribute the campaign to a specific government but was confident about the caliber of the operator. As Craig Williams of Cisco Talos told TechCrunch, this is a new group that is operating in a relatively unique way that we have not seen before, using new tactics, techniques, and procedures, and the team assessed the group's primary motivations are to conduct espionage.
Who was targeted, and what was at stake
The victim list reads like an intelligence collection wishlist. Talos identified the primary targets as national security organizations, ministries of foreign affairs, and prominent energy organizations — exactly the institutions whose internal communications a hostile state would most want to read.
A second tier of victims was, in a sense, even more revealing. Talos found the attackers also hit numerous DNS registrars, telecommunication companies, and internet service providers. These weren't the ultimate prizes; they were the means. By owning the infrastructure providers, the attackers gained the leverage to manipulate DNS for the real targets downstream.
BleepingComputer's summary captured the prize cleanly: the main targets were ministries of foreign affairs, military organizations, intelligence agencies, energy companies. When you can silently intercept the email and login traffic of a foreign ministry, you don't need to break encryption — you can simply harvest the credentials and read the mail as it flows.
How it happened: hijacking the chain of trust

Here is what made Sea Turtle unusually sophisticated: the attackers rarely went straight at their victims. Instead they climbed the chain of trust.
The pattern, as reconstructed by Talos and corroborated by independent reporting, ran roughly like this. First, gain a foothold at a DNS provider, registrar, or registry — typically through spear-phishing or by exploiting a known vulnerability. With that access, modify DNS records to point legitimate users of the target to actor-controlled servers. Those servers were set up as a man-in-the-middle layer: per BleepingComputer, Sea Turtle operators set up a man-in-the-middle (MitM) framework that impersonated legitimate services used by the victim with the purpose of stealing login credentials. Victims would log in to what looked like their normal mail or VPN portal, and the attackers would capture legitimate user credentials when users interacted with these actor-controlled servers, then quietly relay them to the real service so nothing seemed amiss.
The cleverest — and most alarming — piece was how they defeated the padlock. Redirecting traffic is one thing; doing it without triggering a browser certificate warning is another. Sea Turtle solved this by obtaining genuine, valid certificates for the domains they were impersonating. Talos found the attackers obtained a certificate authority-signed X.509 certificate from another provider for the same domain, noting that these actors use Let's Encrypts, Comodo, Sectigo, and self-signed certificates in their MitM servers. Because they controlled the DNS records, they could pass the automated domain-validation checks that free certificate authorities rely on — and walk away with a legitimate green padlock for a domain they did not own.
Brian Krebs, documenting the closely related earlier wave, described the same playbook: the attackers appear to have changed the DNS records for these domains so that the domains pointed to servers in Europe that they controlled, and then were able to obtain SSL certificates for those domains from SSL providers Comodo and/or Let's Encrypt. One of the cited victims was mail.gov.ae, which handles email for government offices of the United Arab Emirates.
Compromised infrastructure providers and a ccTLD registry
The campaign reached infrastructure providers and, later, a country-code top-level-domain registry. Those are distinct roles and incidents.
One publicly confirmed case involved Sweden's Netnod. As Krebs reported, the attackers gained access to accounts at Netnod's domain name registrar, and Netnod itself stated it learned of its role in the attack on January 2. Netnod said it was not the ultimate target but a route used to capture login details for other internet services. This was access through Netnod's registrar account, not evidence that the attackers obtained authority over every country-level namespace or every DNS service Netnod operates.
Talos described the broader significance in stark terms: the operators were responsible for the first publicly confirmed case against an organization that manages a root-server instance. The later compromise of ICS-FORTH, operator of Greece's .gr ccTLD registry, is the campaign's clearer country-code registry case.
Response and aftermath: they didn't stop
DNS hijacking on this scale drew an official response. In January 2019, the U.S. Cybersecurity and Infrastructure Security Agency issued Emergency Directive 19-01, "Mitigate DNS Infrastructure Tampering" — the first emergency directive CISA had ever issued — ordering federal agencies to audit their DNS records, change credentials on DNS management accounts, and enable multi-factor authentication on those accounts. It was a tacit acknowledgment that DNS administration had become a frontline of national security.
What's most striking about Sea Turtle, though, is what happened after it was exposed. Most campaigns go quiet once a vendor like Talos publishes their tradecraft. Sea Turtle did the opposite.
In a July 2019 follow-up, Talos reported that the group had found new victims, including a country code top-level domain (ccTLD) registry, which manages the DNS records for every domain uses that particular country code. Specifically, The Institute of Computer Science of the Foundation for Research and Technology - Hellas (ICS-Forth), the ccTLD for Greece — the body that operates the .gr namespace — was compromised. SecurityWeek noted that even after ICS-Forth publicly acknowledged the breach, Cisco telemetry confirmed that the compromise persisted for at least another five days.
Talos's assessment of the group was unusually pointed: this group appears to be unusually brazen, and will be unlikely to be deterred going forward. They were right. Sea Turtle was not a one-off; it was a demonstration that DNS-layer espionage works, and that the people doing it are willing to keep going in the open.
What this teaches about DNS as critical infrastructure
Strip away the geopolitics and Sea Turtle leaves behind a set of uncomfortable lessons about how the internet's naming layer actually works.
-
DNS is a chain of trust, and you don't control all of it. Your security might be excellent. But your domain's resolution passes through a registrar and a registry, and if either is compromised, your records can be changed without ever touching your network. Sea Turtle proved attackers will deliberately target the link in the chain you have the least visibility into.
-
A valid certificate is not proof of a legitimate destination. The green padlock attests that the connection is encrypted to whoever controls the domain right now — and if an attacker has hijacked the DNS, that's them. Domain-validated certificates are only as trustworthy as the DNS they validate against.
-
DNS manipulation is nearly invisible to the victim. No malware runs on the victim's machines. Endpoint scanners see nothing. The only signal is that records are pointing somewhere they shouldn't — which is exactly why monitoring DNS records for unexpected changes, and locking them down, matters so much.
-
Registrar and registry account security is national-security infrastructure. CISA's first-ever emergency directive was, at its heart, about credentials on DNS management accounts. Multi-factor authentication, registry locks, and tightly controlled access to the accounts that can change DNS records are not hygiene niceties — they are the difference between owning a domain and merely appearing to.
The Namefi angle

Sea Turtle is a story about stolen authority over DNS administration. Registrar, registry, and DNS-provider accounts can change delegation or hosted records independently of the domain's ownership representation.
Namefi provides an on-chain layer for domain ownership and transfer. That can make the tokenized ownership state independently auditable, but DNS resolution and configuration remain in the conventional DNS layer. A compromised registrar or registry can therefore reroute DNS while the on-chain ownership token remains unchanged; tokenization alone does not prevent or necessarily reveal Sea Turtle's attack path.
The relevant defenses are phishing-resistant authentication, least privilege, update-prohibiting controls where supported, DNS and certificate monitoring, and incident response across every provider in the resolution chain. Ownership verification solves a different problem and should not be presented as a substitute for those controls.
Sources and further reading
- Cisco Talos — DNS Hijacking Abuses Trust In Core Internet Service
- Cisco Talos — Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques
- TechCrunch — A new state-backed hacker group is hijacking government domains at a phenomenal pace
- Krebs on Security — A Deep Dive on the Recent Widespread DNS Hijacking Attacks
- BleepingComputer — ‘Sea Turtle’ Campaign Focuses on DNS Hijacking to Compromise Targets
- SecurityWeek — Sea Turtle's DNS Hijacking Continues Despite Exposure
- BankInfoSecurity — ‘Sea Turtle’ DNS Hijacking Group Conducts Espionage: Report
- CISA — Emergency Directive 19-01: Mitigate DNS Infrastructure Tampering
- SDxCentral — Cisco Talos Says a Nation State Is Behind Sea Turtle DNS Hijacking Attacks
- SecurityWeek — State-Sponsored Hackers Use Sophisticated DNS Hijacking in Ongoing Attacks
Contributors
Aileen Wright is a student in her twenties living in New York City, where the distance between a museum wall and a library reading room is a short walk and a long afternoon. She came to name writing through art and history — the way a single portrait, coin, or manuscript margin can carry a name across centuries and change its meaning on the way.
Most weeks you can find her in Central Park with a paperback, or in the quiet of a public reading room chasing down where a name actually comes from rather than what a name-list says it means. She is also teaching herself to code, which has made her oddly precise about spelling, sorting, and the small details that decide whether a name ages well.
For Namefi she writes about the history and culture behind domain names, the stories brands carry as they rename, and the difference between a good story and a verified source.
Victor Zhou is a technology founder and standards editor focused on digital identity and trust. He founded Namefi, edits Ethereum Improvement Proposals, and previously led smart-contract architecture work at Google Labs.
His work sits at the intersection of naming, ownership, and the systems people use to establish identity online. That perspective makes him especially interested in the way names move between personal meaning, public recognition, and digital infrastructure.
For Namefi, Victor edits and writes about domains as durable digital identity: how names become ownable onchain assets, how tokenization changes custody and trust, and what naming can learn from the systems people use to establish identity online.
Related guides
- The $12 Minute: When Google Domains Accepted a Google.com OrderIn September 2015, Google Domains accepted a $12 order for google.com from former employee Sanmay Ved, then canceled it about a minute later. What the incident proves, what remains uncertain, and why the $6,006.13 bounty still matters for domain security.
- Domain Mayday EP03: The 2020 Twitter Bitcoin Account TakeoverOn July 15, 2020, attackers phoned their way into Twitter, hijacked the verified accounts of Obama, Biden, Musk, Gates, Apple and Uber, and ran a Bitcoin doubling scam — netting about $118,000. A deep-dive on how control of an online identity was stolen, and what it teaches about owning a name.
- Domain Mayday EP05: The 2024 Squarespace DeFi Domain Mass-HijackIn July 2024, a registrar migration from Google Domains to Squarespace turned weak default authentication into a mass attack surface. Attackers hijacked the domains of crypto and DeFi projects — Compound Finance, Celer Network, Pendle, Unstoppable Domains — and pointed them at wallet-drainer phishing sites. Here is how a "seamless" migration created hundreds of unlocked front doors, and what it teaches about registrar security and MFA.
- The BadgerDAO Front-End Attack: $120M Drained Through One Injected ScriptIn December 2021, attackers compromised BadgerDAO's Cloudflare account and injected one malicious script into its website front-end. The audited smart contracts were never touched — yet ~$120M walked out the door through wallet approvals users signed without knowing. A deep-dive on why the website is part of your security surface.