Actors Insights|Latest update04/07/2026

Curium

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Curium is Cisco Talos's designation for the Iranian threat cluster known as Imperial Kitten. Talos documented Curium conducting long-term social engineering operations using fake social media personas to build trust with targets before delivering malware — a patient, relationship-based approach that distinguished it from typical phishing operations. The group targeted defense, technology, and government sector organizations. Curium's operational patience and custom .NET-based implants are consistent with the broader Imperial Kitten cluster's IRGC-linked espionage mission.

This threat actor's name is changed to Crimson Sandstorm
First Seen:Dec 2022
Last Seen:Oct 2023
Indexed Reports:0
Public IOCs:0
also known as:
Imperial Kitten (CrowdStrike)Yellow Liderc (PWC)TA456 (Proofpoint)DUSTYCAVECrimson Sandstorm (Microsoft)Cuboid Sandstorm (Microsoft)Smoke Sandstorm (Microsoft)CURIUM (Microsoft)Tortoiseshell (Symantec)G1012 (Mitre)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.