Uptime Hamster: 10d 6h 32mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Tortoiseshell

Tortoiseshell

0 incidentes 0 paises 0 sectores apt IR Ultimo: -
Aliases: CURIUM, Crimson Sandstorm, Cuboid Sandstorm, DUSTYCAVE, IMPERIAL KITTEN, Imperial Kitten, Smoke Sandstorm, TA456, Yellow Liderc, DEV-0228, crimson sandstorm, imperial kitten, ta456, yellow liderc
Ver en IntelTracker → APTTrail →
Tortoiseshell is an Iranian cyber-espionage threat actor that first came to public attention in 2019, though its activity dates back to at least July 2018, initially targeting IT providers in Saudi Arabia through supply chain attacks. The group is assessed with high confidence to be backed by Iran's Islamic Revolutionary Guard Corps (IRGC) and its primary motivation is state-sponsored intelligence gathering. Tortoiseshell distinguishes itself through its patient and prolonged social engineering campaigns, often using fake social media personas to build trust over several weeks or months before delivering malware, and by leveraging supply chain compromises of IT service providers to access their customers. The group operates under several aliases, including CURIUM, Crimson Sandstorm, DUSTYCAVE, IMPERIAL KITTEN, TA456, and Yellow Liderc.

Aliases del actor

CURIUMCrimson SandstormCuboid SandstormDUSTYCAVEIMPERIAL KITTENImperial KittenSmoke SandstormTA456Yellow LidercDEV-0228crimson sandstormimperial kittenta456yellow liderc

Actores similares

crimson-sandstormactor · 1unc1549-crimson-sandstormactor · 1smoke-sandstorm-cuboid-saactor · 1Fox Kittenapt · 1Charming Kittenactor · 1cutting-kittenactor · 1clever-kittenactor · 1charming-kittenactor · 1rocket-kittenactor · 1flash-kittenactor · 1
Motivacion