CURIUM

APT / StateG1012
Origin🇮🇷 Irã
Techniques (MITRE ATT&CK)19
SourceMITRE ATT&CK
State sponsor: Iran (Islamic Republic of)Attribution confidence: 50%Target categories: Defense, Government, Military, Finance, Energy, Healthcare, Pharmaceuticals, Telecoms, High-Tech, Media, NGOs, Civil Society, Legal, Rail, Transportation
Targeted regions: United States · Israel · Middle East · Europe
Also known as:Crimson SandstormCuboid SandstormDUSTYCAVEIMPERIAL KITTENImperial KittenSmoke SandstormTA456Tortoise ShellYellow Liderc

Vexday analysis

CURIUM é um grupo de ameaça persistente avançada (APT) de origem iraniana, reportado pela primeira vez em setembro de 2019 e ativo desde pelo menos julho de 2018, com atuação documentada contra provedores de serviços de TI no Oriente Médio. O grupo é reconhecido por cultivar relacionamentos com alvos potenciais por meio de redes sociais ao longo de meses, estabelecendo confiança gradualmente antes de entregar malware — chegando a manter conversas diárias e enviar arquivos benignos para reduzir a vigilância dos alvos. Rastreado pelo MITRE ATT&CK sob o identificador G1012, o CURIUM possui 19 técnicas documentadas na base de conhecimento, sendo também conhecido pelos aliases Crimson Sandstorm, TA456, Tortoise Shell e Yellow Liderc.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity31
Impact: High
T1189T1059.001T1505.003T1082T1005ENTRYInitial accessDrive-byCompromiseEXECExecutionPowerShellPERSPersistenceWeb ShellDISCDiscoverySystem InformationDiscoveryCOLLCollectionData from LocalSystemEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

CURIUM uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →