← Threat Actors / Iran / Tortoiseshell
DOSSIER // TORTOISESHELL

Tortoiseshell

▲ High Threat Iran
Primary Aliases: Crimson Sandstorm Cuboid Sandstorm IMPERIAL KITTEN Smoke Sandstorm
Sponsor / State Affiliation Iran (Islamic Republic of)
Primary Motivation Espionage
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providers’ customers. The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access.

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Defense Government Military Finance Energy Healthcare Pharmaceuticals Telecoms High-Tech Media NGOs Civil Society Legal Rail Transportation

🛡️ MITRE ATT&CK® Attack Lifecycle (0 TTPs)

📥 Download Navigator JSON
No tactical TTP mapping records recorded in database.

📰 Verified Campaigns & Intelligence Archive

🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Copied to clipboard

LINK COPIED TO CLIPBOARD