Curium
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranCurium is Cisco Talos's designation for the Iranian threat cluster known as Imperial Kitten. Talos documented Curium conducting long-term social engineering operations using fake social media personas to build trust with targets before delivering malware — a patient, relationship-based approach that distinguished it from typical phishing operations. The group targeted defense, technology, and government sector organizations. Curium's operational patience and custom .NET-based implants are consistent with the broader Imperial Kitten cluster's IRGC-linked espionage mission.
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.