CURIUM
Also reported as Crimson Sandstorm, TA456, Yellow Liderc, Smoke Sandstorm, UNC1549 and 19 other names. Linked to Iran by four sources.
Reports per quarter
Techniques seen in the last two years
- T1041 3 reports in ATT&CK
- T1053.005 3 reports reports only
- T1189 3 reports in ATT&CK
- T1219 3 reports reports only
- T1566.001 3 reports in ATT&CK
- T1566.002 3 reports reports only
- T1016 2 reports reports only
- T1021.001 2 reports reports only
- T1021.002 2 reports reports only
- T1021.004 2 reports reports only
Show all 250 techniques Show fewer
- T1027 2 reports reports only
- T1033 2 reports reports only
- T1055.001 2 reports reports only
- T1056 2 reports reports only
- T1059.001 2 reports in ATT&CK
- T1059.003 2 reports reports only
- T1059.007 2 reports reports only
- T1082 2 reports in ATT&CK
- T1083 2 reports reports only
- T1091 2 reports reports only
- T1133 2 reports reports only
- T1190 2 reports reports only
- T1195 2 reports reports only
- T1204.002 2 reports in ATT&CK
- T1505.003 2 reports in ATT&CK
- T1547.001 2 reports reports only
- T1566.003 2 reports in ATT&CK
- T1572 2 reports reports only
- T1574 2 reports reports only
- T1584 2 reports reports only
- T1585.002 2 reports in ATT&CK
- T1592 2 reports reports only
- T1003 1 report reports only
- T1003.001 1 report reports only
- T1003.002 1 report reports only
- T1005 1 report in ATT&CK
- T1007 1 report reports only
- T1008 1 report reports only
- T1010 1 report reports only
- T1012 1 report reports only
- T1016.001 1 report reports only
- T1018 1 report reports only
- T1020 1 report reports only
- T1021 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1036.004 1 report reports only
- T1036.005 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1046 1 report reports only
- T1047 1 report reports only
- T1049 1 report reports only
- T1053 1 report reports only
- T1053.003 1 report reports only
- T1055 1 report reports only
- T1055.002 1 report reports only
- T1055.003 1 report reports only
- T1055.004 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056.001 1 report reports only
- T1056.003 1 report reports only
- T1057 1 report reports only
- T1059 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.005 1 report reports only
- T1059.006 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1068 1 report reports only
- T1069 1 report reports only
- T1069.001 1 report reports only
- T1069.002 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1070.004 1 report reports only
- T1070.006 1 report reports only
- T1071 1 report reports only
- T1071.001 1 report reports only
- T1071.003 1 report reports only
- T1071.004 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078 1 report reports only
- T1078.002 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.001 1 report reports only
- T1087.002 1 report reports only
- T1087.004 1 report reports only
- T1090 1 report reports only
- T1090.001 1 report reports only
- T1090.003 1 report reports only
- T1095 1 report reports only
- T1098 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1098.007 1 report reports only
- T1102 1 report reports only
- T1102.001 1 report reports only
- T1102.002 1 report reports only
- T1104 1 report reports only
- T1105 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1119 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1124 1 report in ATT&CK
- T1125 1 report reports only
- T1129 1 report reports only
- T1132 1 report reports only
- T1132.001 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1135 1 report reports only
- T1136 1 report reports only
- T1136.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1140 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report reports only
- T1204 1 report reports only
- T1204.001 1 report reports only
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1217 1 report reports only
- T1218 1 report reports only
- T1482 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1486 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1496 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1505 1 report reports only
- T1505.004 1 report reports only
- T1518 1 report reports only
- T1518.001 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.003 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1554 1 report reports only
- T1556 1 report reports only
- T1556.002 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1559 1 report reports only
- T1560 1 report reports only
- T1560.001 1 report reports only
- T1560.002 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566 1 report reports only
- T1566.004 1 report reports only
- T1567 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1570 1 report reports only
- T1571 1 report reports only
- T1573 1 report reports only
- T1573.001 1 report reports only
- T1573.002 1 report reports only
- T1574.001 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583 1 report reports only
- T1583.003 1 report in ATT&CK
- T1585 1 report reports only
- T1587 1 report reports only
- T1587.001 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1595 1 report reports only
- T1595.002 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608 1 report reports only
- T1608.001 1 report reports only
- T1608.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report in ATT&CK
- T1608.005 1 report reports only
- T1608.006 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2013-4786
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2018-0171 KEV
- CVE-2018-0798 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-8440 KEV ransomware
Show all 91 CVEs Show fewer
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-9670 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12641 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-40444 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20273 KEV
- CVE-2023-23397 KEV
- CVE-2023-27532 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-38950 KEV
- CVE-2023-3895037
- CVE-2023-38951
- CVE-2023-3895138
- CVE-2023-38952
- CVE-2023-3895239
- CVE-2023-42793 KEV ransomware
- CVE-2023-46747 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-3400 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-47575 KEV
- CVE-2024-9474 KEV ransomware
- CVE-2024-9680 KEV ransomware
- CVE-2025-29824 KEV ransomware
- CVE-2025-31324 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-4427 KEV
- CVE-2025-4428 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Tortoiseshell, Imperial Kitten - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Tortoiseshell, Imperial Kitten - Threat Group Cards: A Threat Actor Encyclopedia
Show all 67 reports Show fewer
-
Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor When Cats Fly_ Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors _ Mandiant
-
Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Above the Fold and in Your Inbox- Tracing State-Aligned Activity Targeting Journalists, Media
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Above the Fold and in Your Inbox- Tracing State-Aligned Activity Targeting Journalists, Media
-
Complaint filed by Microsoft Digital Crimes Unit against BOHRIUM, a Iranian threat actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Complaint filed by Microsoft Digital Crimes Unit against BOHRIUM, a Iranian threat actor
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
Social Engineering Remains Key Tradecraft for Iranian APTs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Social Engineering Remains Key Tradecraft for Iranian APTs
-
Iranian targeting of IT sector on the rise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian targeting of IT sector on the rise
-
Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor I Knew You Were Trouble_ TA456 Targets Defense Contractor with Alluring Social Media Persona _ Proofpoint US
-
I Knew You Were Trouble- TA456 Targets Defense Contractor with Alluring Social Media Persona
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor I Knew You Were Trouble- TA456 Targets Defense Contractor with Alluring Social Media Persona
-
Taking Action Against Hackers in Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taking Action Against Hackers in Iran
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Current Iran-Associated Cyber Threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Current Iran-Associated Cyber Threats
-
How Tortoiseshell created a fake veteran hiring website to host malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Tortoiseshell created a fake veteran hiring website to host malware
-
Iranian Government Hackers Target US Veterans
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Government Hackers Target US Veterans
-
How Tortoiseshell created a fake veteran hiring website to host malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor How Tortoiseshell created a fake veteran hiring website to host malware
-
Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
-
Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
-
Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks
Newest first. Details opens the report in Explore.