← Back to all threat actors

CURIUM

Also known as Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc
Tracked as G1012

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1012

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Crimson Sandstorm

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TA456

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Tortoise Shell

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Yellow Liderc

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

CURIUMCanonical Name
Crimson SandstormAlias
TA456Alias
Tortoise ShellAlias
Yellow LidercAlias
G1012Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...