Tortoiseshell is an Iranian state-aligned cyberespionage actor active since at least 2018 and associated with Iran’s Islamic Revolutionary Guard Corps (IRGC). It is also tracked as CURIUM, Crimson Sandstorm, TA456, Imperial Kitten, and Yellow Liderc. Related activity clusters include Mirage Kitten, UNC1549, and Nimbus Manticore. Its principal targets include defense and aerospace companies, military personnel and organizations, and IT service providers, particularly in the United States and the Middle East, with additional confirmed targeting in the United Kingdom and Europe. Smaller defense subcontractors and subsidiaries are targeted as potential routes into larger contractors. Part of its malware development has been linked to Mahak Rayan Afraz, a Tehran-based IT company with IRGC ties. The actor combines prolonged, cross-platform social engineering with credential phishing and malware delivery. Operators maintain convincing fictitious personas, sometimes engaging targets for months or years, and impersonate recruiters and defense-company employees. Initial-access methods include fake recruitment portals, malicious links and macro-enabled spreadsheets, watering-hole attacks, and supply-chain compromises. Phishing infrastructure harvests credentials for corporate and personal email, collaboration platforms, and social media. Its tooling includes Syskit, Liderc, LEMPO, and custom remote-access and reconnaissance implants. LEMPO collects extensive host and network information, establishes logon persistence, exfiltrates collected information over encrypted email, and removes collection artifacts. Other tools include keystroke loggers, reverse SSH tunneling utilities, and a C++ backdoor resembling TWOSTROKE. The latter uses DLL search-order hijacking, runtime string decryption, and HTTPS command-and-control, supporting command execution, file transfer and theft, in-memory DLL execution, and host and directory reconnaissance. These capabilities support persistent access and intelligence collection within compromised environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
92 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian state-sponsored espionage actor targeting defense, aerospace, IT-service, and military organizations. The group uses reverse SSH tunnels and the TWOSTROKE backdoor to maintain command-and-control access, execute commands and DLLs, transfer files, conduct host and directory discovery, and exfiltrate data.
Iranian IRGC-affiliated espionage actor expanding operational infrastructure across Europe and the Middle East and deploying an SSH-tunneling tool and a TWOSTROKE-like C++ backdoor for reconnaissance, command execution, file transfer, and data exfiltration.
Iranian-linked cyber-espionage activity cluster active since at least July 2018. It primarily targets defense and aerospace sectors, IT providers, and military organizations in the Middle East and the United States, and continues to develop SSH-tunneling and backdoor capabilities for persistent access.
A threat-activity cluster identified as associated with Nimbus Manticore in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.