Actors Insights|Latest update09/04/2026

Curium

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran
This threat actor's name is changed to Crimson Sandstorm
First Seen:Unknown
Last Seen:Unknown
Indexed Reports:0
Public IOCs:0
Cluster: TortoiseshellMitre: CURIUMMisp: Tortoiseshell
also known as:
Imperial Kitten (CrowdStrike)Yellow Liderc (PWC)TA456 (Proofpoint)DUSTYCAVECrimson Sandstorm (Microsoft)Tortoiseshell (Symantec)CURIUM (Microsoft)G1012 (Mitre)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.