Uptime Hamster: 10d 9h 7mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Sima

Sima

0 incidentes 0 paises 0 sectores apt IR Ultimo: -
Aliases: IMAPLoader, APT MINIDUKE, APT TICK, apolloshadow, atg26, blue python, kazuar, kypton, snake, storm-0156, uroburos, venomous bear, wainscot, waterbug
Ver en IntelTracker → APTTrail →
Sima is a state-sponsored threat group of Iranian origin, first documented in February 2016. The group's primary motivation is information theft and espionage, distinguishing itself through highly refined spear-phishing tactics that incorporate detailed background research and legitimate-looking baits to increase success rates. Sima has demonstrated an evolution in its social engineering techniques, using malware binaries disguised with right-to-left filenames to conceal actual file extensions and appropriating real identities to interact professionally with targets. This approach represents a notable refinement compared to other groups that rely on more generic attack methods.

Aliases del actor

IMAPLoaderAPT MINIDUKEAPT TICKapolloshadowatg26blue pythonkazuarkyptonsnakestorm-0156uroburosvenomous bearwainscotwaterbug

Actores similares

apt-blueprintactor · 1apt-minidukeactor · 1apt-noisybearactor · 1apt-tickactor · 1APT29 (Cozy Bear)actor · 1Energetic Bearapt · 0Boulder Bearapt · 0Pat Bearapt · 0White Bearapt · 0apt-45actor · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownduckduckgo.comasimar.com
DLS / leak siteunknownduckduckgo.comasimar.com
Motivacion