CURIUM

APT / StateG1012 ↗
Origin🇮🇷 Irã
Techniques (MITRE ATT&CK)19
SourceMITRE ATT&CK
State sponsor: Iran (Islamic Republic of)Attribution confidence: 50%Target categories: Defense, Government, Military, Finance, Energy, Healthcare, Pharmaceuticals, Telecoms, High-Tech, Media, NGOs, Civil Society, Legal, Rail, Transportation
Targeted regions: United States · Israel · Middle East · Europe
Also known as:Crimson SandstormCuboid SandstormDUSTYCAVEIMPERIAL KITTENImperial KittenSmoke SandstormTA456Tortoise ShellYellow Liderc

About the group

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity31
Impact: High
T1189T1059.001T1505.003T1082T1005ENTRYInitial accessDrive-byCompromiseEXECExecutionPowerShellPERSPersistenceWeb ShellDISCDiscoverySystem InformationDiscoveryCOLLCollectionData from LocalSystemEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

CURIUM uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →