◇ SIGN IN
← all actors
apt

Imperial Kitten (CURIUM)

activehigh confidence
APT / State-sponsored
CURIUMTortoiseshellCrimson SandstormTA456Yellow LidercCuboid Sandstorm
Attribution
Iran-nexus espionage group assessed to support IRGC intelligence requirements
Origin
Iran
First seen
2019
Last active
2026
Motivation
Espionage
Confidence
high
MENA targeting
Israel (primary), broader Middle East tech sector
Sectors
Transportation, logistics, technology, maritime, telecom, defense
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Israel (primary), broader Middle East tech sector (Transportation, logistics, technology sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Imperial Kitten (MITRE CURIUM, G1012; aka Tortoiseshell/Crimson Sandstorm) is an Iran-nexus espionage actor known for patient social-engineering, fake personas and watering-hole attacks against IT, maritime, transportation and technology targets, especially in Israel and the Gulf.

History

The cluster was first reported in September 2019 (as Tortoiseshell by Symantec) targeting IT service providers in Saudi Arabia, and MITRE tracks it as CURIUM (G1012), active since at least 2018. CrowdStrike's 'Imperial Kitten' and Microsoft's 'Crimson Sandstorm' (previously Curium) label the same Iran-nexus activity, assessed to serve IRGC strategic intelligence needs.

The group is defined by relationship-building tradecraft: operators cultivate fake social-media personas (often posing as recruiters or attractive contacts), chatting with targets over weeks or months and sending benign files to lower suspicion before delivering malware. TTPs include recruitment-themed phishing with malicious Office documents, custom .NET implants and downloaders, and JavaScript watering-hole implants planted on compromised Israeli websites to profile visitors.

MENA targeting is central. Following the October 2023 Israel-Hamas war, CrowdStrike documented Imperial Kitten phishing (job-recruitment lures with malicious Excel) and 2022-2023 watering-hole activity against Israeli maritime, shipping, logistics and technology sectors. Reporting through 2025-2026 (including SecurityScorecard analysis of IRGC-linked collectives during the 2025-2026 Israel-Iran conflict) indicates the group adapted operations to align with Iran's kinetic activity.

Confidence in the activity is high (multi-vendor); the IRGC-alignment attribution is medium-to-high, consistent across CrowdStrike, Microsoft and Symantec reporting.

Notable campaigns

2019
Tortoiseshell (initial disclosure)
Symantec exposed supply-chain-style targeting of Saudi IT service providers using custom backdoors and info-stealers.
2022-2023
Israeli watering holes
Compromised Israeli websites with JavaScript to profile visitors in maritime, shipping and logistics sectors.
2023
Post-Oct-7 recruitment phishing
CrowdStrike documented job-themed phishing with malicious Excel delivering implants to Israeli technology and transport targets amid the Israel-Hamas war.