Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CURIUM

Also known as: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc, IMPERIAL KITTEN, DUSTYCAVE, Cuboid Sandstorm, Smoke Sandstorm, CURIUM, APT34, tracked as, Mustang Panda, Helix Kitten

Description

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East.(Citation: Symantec Tortoiseshell 2019) CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.(Citation: Microsoft Iranian Threat Actor Trends November 2021)

Goals & Targeting

Targeted Sectors

Defense
Government
Financial services
Energy
Healthcare
Pharmaceutical
Telecommunications
Media
Non profit
Legal services
Transportation
Nuclear
Maritime
Aerospace
Critical infrastructure
Education

Targeted Countries / Regions

IR
UA
SA
US
IL
CN
NL

AI Analysis

· 1 week ago

Executive Summary

CURIUM, an Iranian-based advanced persistent threat (APT) group first reported in September 2019 and active since July 2018, targets a wide range of sectors including defense, government, healthcare, energy, and financial services. Known for patient social engineering tactics to establish trust before deploying malware, CURIUM is suspected to use a variety of techniques like spear-phishing and drive-by attacks to achieve its objectives.

Goals & Targeting

CURIUM targets sectors of significant economic and political importance to gather sensitive information or disrupt operations. Their focus on diverse industries indicates a goal of gathering broad intelligence capabilities or achieving multiple strategic objectives. The group's activities likely serve both espionage and potential disruptive purposes, aligning with broader Iranian interests in critical infrastructure and geopolitical influence.

Enhanced Description

CURIUM, also known as Crimson Sandstorm or TA456, operates with high sophistication, leveraging prolonged social engineering campaigns on social media platforms to lower targets' defenses. Initially targeting IT service providers in the Middle East, CURIUM has expanded its reach to include multiple global sectors. Their modus operandi involves sending benign files and establishing trust over time before deploying malicious payloads. The group has demonstrated persistence and adaptability since its inception in 2018. While their primary motivations remain unclear, their targeting patterns suggest strategic interests aligned with broader geopolitical objectives.

Key Capabilities

  • Social engineering via prolonged engagement on social media
  • Spear-phishing campaigns
  • Drive-by malware attacks
  • Use of web shells for persistence
  • Exfiltration techniques using encrypted channels
  • Malware development and deployment

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1204.002: Malicious File
T1598.003: Spearphishing Link
T1566.001: Spearphishing Attachment
T1608.004: Drive-by Target
T1082: System Information Discovery
T1005: Data from Local System
T1583.001: Domains
T1505.003: Web Shell
T1585.002: Email Accounts
T1048.002: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
T1041: Exfiltration Over C2 Channel
T1059.001: PowerShell

Software / Tooling

IMAPLoader

Campaigns & Victims

CURIUM has been observed in multiple campaigns primarily targeting Middle Eastern countries, though their operations may extend to global entities in strategic sectors. Their operational tempo suggests continuous activity since 2018, with a focus on maintaining persistence and ensuring long-term access through patient engagement periods.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Use of IMAPLoader malware
  • Social media engagement prior to attack
  • Scheduled tasks or scripts executed in PowerShell

Recommended Actions

  • Implement multi-factor authentication (MFA) for email and cloud services.
  • Monitor for persistent actors using tools like IMAPLoader.
  • Enhance phishing detection mechanisms with AI-based solutions.
  • Conduct regular network segmentation reviews to limit lateral movement.
  • Employ endpoint detection and response (EDR) solutions.

Suggested Tags

APT
Cyber Espionage
Geopolitical
Healthcare
Energy

Confidence Assessment

Confidence in CURIUM's details is moderate due to linked MITRE techniques, but gaps exist regarding specific campaigns and IOC types. Limited specificity on tools aside from IMAPLoader leaves some ambiguity.

ATT&CK Techniques

Resource Development
11 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  2. Proofpoint TA456 Defense Contractor July 2021 — Miller, J. et. al. (2021, July 28). I Knew You Were Trouble: TA456 Targets Defense Contractor with Alluring Social Media Persona. Retrieved March 11, 2024.
  3. Microsoft Iranian Threat Actor Trends November 2021 — MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.
  4. PWC Yellow Liderc 2023 — PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.
  5. Symantec Tortoiseshell 2019 — Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.
  6. attack.mitre.org — Cited by web research for: Mustang Panda
  7. attack.mitre.org — Cited by web research for: T1505
  8. www.huntress.com — Cited by web research for: IMAPLoader
  9. apt.etda.or.th — Cited by web research for: Maritime
  10. www.microsoft.com — Cited by web research for: Microsoft Teams
  11. www.microsoft.com — Cited by web research for: 8b864ea2c8879287e5f14e59784ce899

Intel Summary

34

Techniques

51

Tools

0

Campaigns

14

IOCs

0

Observed Data

8

Tactics

Tags

APT
Cyber Espionage
Geopolitical
Healthcare
Energy

Details

MITRE ID
G1012
Type
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--3ea7add5-5b8f-45d8-b1f1-905d2729d62a
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.