NEW: Group Profiler — instant APT intel lookup. Try it →

CURIUM

G1012 Iran Espionage MITRE ATT&CK →

Also known as: Crimson Sandstorm · TA456 · Tortoise Shell · Yellow Liderc

Overview

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.

Naming & attribution

CURIUM is tracked under 5 names across the industry. It uses 19 documented ATT&CK techniques — more than 51% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Crimson SandstormMicrosoft
TA456Microsoft
Tortoise ShellMicrosoft
Yellow LidercPwC Threat Intelligence

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

Targets

Civil society · Defense · Energy · Finance · Government · Healthcare · High-Tech · Legal · Media · Military · NGOs · Pharmaceuticals · Rail · Telecommunications · Transportation

Regions

Europe · Israel · Middle East · United States

TTPs — 19 techniques across 8 tactics

Reconnaissance

Resource Development

Execution

Persistence

Collection

Tools & malware (1)

IMAPLoader

Reporting (3)