Tortoiseshell is an Iranian state-linked cyber-espionage actor active since at least 2018 and assessed as operating in support of, or affiliated with, Iran’s Islamic Revolutionary Guard Corps (IRGC). It is also tracked as CURIUM, Crimson Sandstorm, TA456, Mirage Kitten, UNC1549, Nimbus Manticore, Imperial Kitten, Yellow Liderc, and Tortoise Shell. Portions of its malware-development activity have been linked to Tehran-based IT company Mahak Rayan Afraz, which has reported ties to the IRGC. The group has principally targeted defense, aerospace, military, technology, information-technology service-provider, telecommunications, and aviation organizations, particularly in the United States and Middle East, with documented targeting also affecting the United Kingdom and Europe. It has placed particular emphasis on defense-industry personnel, subcontractors, and subsidiaries whose access could provide a route to larger prime contractors. Tortoiseshell combines prolonged social engineering with technical intrusion activity. Operators have used fabricated online personas, including recruiter-themed identities, to establish trust over social-media platforms and email before delivering malicious documents or credential-phishing lures. They have operated spoofed recruitment and job-search sites and impersonated trusted services to harvest credentials and profile victim devices. The group has also used supply-chain compromises, compromised websites and watering holes, and fake application installers for initial access. Its tooling includes custom Windows remote-access malware, the Syskit malware family, Liderc and its LEMPO variant, keystroke loggers, reconnaissance utilities, reverse SSH tunneling components, and a backdoor resembling TWOSTROKE. Observed implants support host and network discovery, directory enumeration, command and shell execution, file transfer, in-memory DLL loading, credential-related file searching, and data theft over encrypted web, email, and command-and-control channels. Tortoiseshell has used DLL search-order hijacking and masquerading to establish access, persistence mechanisms including user logon execution, and artifact deletion to hinder forensic analysis. Reverse SSH tunnels enable outbound access paths into compromised networks and may facilitate follow-on internal access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
90 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian-linked espionage actor assessed to be expanding its infrastructure footprint and potential geographic reach into Britain, Europe, and the Middle East. It continues to use a TwoStroke-like backdoor and a reverse SSH tunneling tool for encrypted access into compromised networks and possible internal-network reach.
Iranian-linked cyber-espionage group expanding its toolset with a C++ backdoor and a reverse SSH tunneling utility. It targets defense, aerospace, IT service providers, and military organizations, with infrastructure suggesting possible broader targeting across Europe and the Middle East.
Iran-linked espionage activity targeting Middle Eastern and European organizations. The group deploys reverse SSH tunnels and a TWOSTROKE-like backdoor for persistent access, command execution, file transfer and theft, in-memory DLL loading, reconnaissance, and C2 over HTTPS. Documented initial-access methods include supply-chain compromise, compromised websites, and fake recruitment portals.
Iranian state-aligned espionage actor expanding infrastructure and apparent targeting across the Middle East and Europe. It uses supply-chain compromises, watering-hole attacks, fake recruitment sites, custom backdoors, reverse SSH tunneling, and a TWOSTROKE-like backdoor to maintain access, execute commands, conduct reconnaissance, and exfiltrate files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.