Imperial Kitten (MITRE CURIUM, G1012; aka Tortoiseshell/Crimson Sandstorm) is an Iran-nexus espionage actor known for patient social-engineering, fake personas and watering-hole attacks against IT, maritime, transportation and technology targets, especially in Israel and the Gulf.
The cluster was first reported in September 2019 (as Tortoiseshell by Symantec) targeting IT service providers in Saudi Arabia, and MITRE tracks it as CURIUM (G1012), active since at least 2018. CrowdStrike's 'Imperial Kitten' and Microsoft's 'Crimson Sandstorm' (previously Curium) label the same Iran-nexus activity, assessed to serve IRGC strategic intelligence needs.
The group is defined by relationship-building tradecraft: operators cultivate fake social-media personas (often posing as recruiters or attractive contacts), chatting with targets over weeks or months and sending benign files to lower suspicion before delivering malware. TTPs include recruitment-themed phishing with malicious Office documents, custom .NET implants and downloaders, and JavaScript watering-hole implants planted on compromised Israeli websites to profile visitors.
MENA targeting is central. Following the October 2023 Israel-Hamas war, CrowdStrike documented Imperial Kitten phishing (job-recruitment lures with malicious Excel) and 2022-2023 watering-hole activity against Israeli maritime, shipping, logistics and technology sectors. Reporting through 2025-2026 (including SecurityScorecard analysis of IRGC-linked collectives during the 2025-2026 Israel-Iran conflict) indicates the group adapted operations to align with Iran's kinetic activity.
Confidence in the activity is high (multi-vendor); the IRGC-alignment attribution is medium-to-high, consistent across CrowdStrike, Microsoft and Symantec reporting.