MurenShark
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
MurenShark is the alias used for a threat actor that has been observed in open-source reporting. The actor’s location is noted as Turkey when known. MurenShark has been attributed to a cyber espionage operation targeting Turkey’s indigenous submarine management system project. The operation occurred in August 2022 and focused on personnel associated with the Naval Forces Command and TÜBİTAK staff. Initial access was achieved through phishing campaigns that delivered malicious documents masquerading as legitimate correspondence from those institutions. The malicious documents were observed to contain the AgentTesla malware family. For command and control, the group leveraged a compromised website belonging to a Cypriot university as a long‑term server. These tactics reflect a focus on stealthy persistence and the use of widely available malware tools.
Security analysts have assessed that MurenShark possesses advanced capabilities to obfuscate its origins and operational footprint. While the definitive success of the intrusion has not been confirmed, analysts noted evidence suggesting potential system compromise based on stolen document content and control of the C2 infrastructure. No public attribution to a state sponsor, criminal consortium, or other affiliations has been established for MurenShark. The August 2022 submarine‑project intrusion remains the only publicly reported campaign linked to this alias. Consequently, the profile is limited to the observed targeting of defense‑related personnel, the use of phishing with AgentTesla, and the Cypriot university C2 server. Any further conclusions about the actor’s motives, size, or broader activity would require additional verified information.
Incidents
Attributed incidents are available to members.
1 incident