CURIUM

MITRE ATT&CK: G1012 View on attack.mitre.org

Aliases: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc, IMPERIAL KITTEN, Imperial Kitten, DUSTYCAVE, Cuboid Sandstorm, Smoke Sandstorm, CURIUM, BOHRIUM, HOUSEBLEND, UNC1549

First seen
2018-07-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
Espionage
Related IoCs
4 (4 malicious)
Last IoC activity
2026-03-30 21:29:18
Profile updated
2026-07-07 12:31:04

Targeted industries: technology-and-telecommunications government-and-public-sector professional-services

Targeted regions: country_code:sa country_code:ae

Context

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to CURIUM (G1012). The 4 most recently updated:

TypeIndicatorUpdatedSources
file sample 179671da8b4e9fca2c0eabeb207446af67cc08dc22c61d89badfb3d38fd6cac3 2026-03-30 1
file sample AstraluxClient-1.21.1.jar 2026-03-06 1
file sample cebd4f2c494b43171b767db45c9d44dd482c287ea5d0aa698340304b212a5c3d.file 2026-03-05 1
file sample KryptonCracked-1.21-1.21.1.jar 2026-03-04 1

Detection coverage

  • 1 YARA rules
  • 299 Sigma rules

Malware & tools used

  • Spearphishing via Service (attack-pattern)
  • Web Shell (attack-pattern)
  • Malicious File (attack-pattern)
  • Web Services (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Drive-by Target (attack-pattern)
  • Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (attack-pattern)
  • Data from Local System (attack-pattern)
  • Social Media Accounts (attack-pattern)
  • Email Accounts (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • PowerShell (attack-pattern)
  • Domains (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Server (attack-pattern)
  • IMAPLoader (malware)

Reports & references

  • Microsoft — Evolving Trends In Iranian Threat Actor Activity Mstic Presentation At Cyberwarcon 2021 (report)
  • services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
  • Broadcom/Symantec — Tortoiseshell Apt Supply Chain (report)
  • darkreading.com — 1335897 (report)
  • ctoatncsc.substack.com — Cto At Ncsc Summary Week Ending October (report)
  • pwc.com — Yellow Liderc Ships Its Scripts Delivers Imaploader Malware (report)
  • ics-cert.kaspersky.com — Apt And Financial Attacks On Industrial Organizations In H1 2023 (report)
  • twitter.com — 1532398956918890500 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G1012 (report)
  • Broadcom/Symantec — Tortoiseshell Apt Supply Chain (report)
  • proofpoint.com — I Knew You Were Trouble Ta456 Targets Defense Contractor Alluring Social Media (report)

External references