Also known as: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc, IMPERIAL KITTEN, DUSTYCAVE, Cuboid Sandstorm, Smoke Sandstorm, CURIUM, APT34, tracked as, Mustang Panda, Helix Kitten
CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East.(Citation: Symantec Tortoiseshell 2019) CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.(Citation: Microsoft Iranian Threat Actor Trends November 2021)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CURIUM, an Iranian-based advanced persistent threat (APT) group first reported in September 2019 and active since July 2018, targets a wide range of sectors including defense, government, healthcare, energy, and financial services. Known for patient social engineering tactics to establish trust before deploying malware, CURIUM is suspected to use a variety of techniques like spear-phishing and drive-by attacks to achieve its objectives.
Goals & Targeting
CURIUM targets sectors of significant economic and political importance to gather sensitive information or disrupt operations. Their focus on diverse industries indicates a goal of gathering broad intelligence capabilities or achieving multiple strategic objectives. The group's activities likely serve both espionage and potential disruptive purposes, aligning with broader Iranian interests in critical infrastructure and geopolitical influence.
Enhanced Description
CURIUM, also known as Crimson Sandstorm or TA456, operates with high sophistication, leveraging prolonged social engineering campaigns on social media platforms to lower targets' defenses. Initially targeting IT service providers in the Middle East, CURIUM has expanded its reach to include multiple global sectors. Their modus operandi involves sending benign files and establishing trust over time before deploying malicious payloads. The group has demonstrated persistence and adaptability since its inception in 2018. While their primary motivations remain unclear, their targeting patterns suggest strategic interests aligned with broader geopolitical objectives.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CURIUM has been observed in multiple campaigns primarily targeting Middle Eastern countries, though their operations may extend to global entities in strategic sectors. Their operational tempo suggests continuous activity since 2018, with a focus on maintaining persistence and ensuring long-term access through patient engagement periods.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in CURIUM's details is moderate due to linked MITRE techniques, but gaps exist regarding specific campaigns and IOC types. Limited specificity on tools aside from IMAPLoader leaves some ambiguity.
No campaigns linked yet.
No observed data linked yet.
34
Techniques
51
Tools
0
Campaigns
14
IOCs
0
Observed Data
8
Tactics