Threat intelligence
- Suspected origin
- Iran
- First seen
- 2018-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Aerospace, Defense, IT, Shipping and Logistics, Maritime and Shipbuilding
- TLP
- WHITE
(Symantec) A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providers’ customers.
The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access.
Overlap has been found with Magic Hound’s Subgroup: TA455, Smoke Sandstorm.
Also known as
Cobalt FiresideCrimson SandstormCuboid SandstormCuriumDevious SerpensHouseblendImperial KittenMarcella FloresTA456Tortoise ShellTortoiseshellYellow Liderc
Tooling and malware
IMAPLoader
MITRE ATT&CK techniques
T1005 Data from Local SystemT1082 System Information DiscoveryT1124 System Time DiscoveryT1041 Exfiltration Over C2 ChannelT1189 Drive-by Compromise
Coverage 1
threat-intel
Iranian-linked hackers, known as Tortoiseshell, are expanding their operations across Europe and the Middle East, including establishing infrastructure in Britain. The group, associated with Iran's Islamic Revolutionary…
