Actors Insights|Latest update04/07/2026

Tortoiseshell

Named by SymantecSuspected state sponsor: Islamic Republic of Iran

Tortoiseshell is Symantec's designation for the Iranian threat cluster known as Imperial Kitten, active since at least 2018. The group targets IT managed service providers (MSPs) and supply chain companies to gain downstream access to defense and government networks in the Middle East and the United States. Symantec documented campaigns in which Tortoiseshell compromised IT firms serving Saudi Arabian defense contractors, using custom malware including Sartoruis and Backdoor.Dituran for persistence and data collection. The cluster shares IRGC attribution and targeting patterns with the broader Imperial Kitten, TA456, and Crimson Sandstorm identities.

First Seen:Jul 2018
Last Seen:Nov 2025
Indexed Reports:4
Public IOCs:237
also known as:
Imperial Kitten (CrowdStrike)Yellow Liderc (PWC)TA456 (Proofpoint)DUSTYCAVECrimson Sandstorm (Microsoft)Cuboid Sandstorm (Microsoft)Smoke Sandstorm (Microsoft)CURIUM (Microsoft)Tortoiseshell (Symantec)G1012 (Mitre)

Targeted Regions

Israel
IL
Israel
Israel
May 2022 ~ May 2023
May 2022 ~ May 2023
May 2022 ~ May 2023
May 2022 ~ May 2023
Saudi Arabia
SA
Saudi Arabia
Saudi Arabia
Jul 2018 ~ Sep 2019
Jul 2018 ~ Sep 2019
Jul 2018 ~ Sep 2019
Jul 2018 ~ Sep 2019
United Kingdom
GB
United Kingdom
United Kingdom
Jul 2021 ~ Jul 2021
United States
US
United States
United States
Sep 2019 ~ Sep 2019
Jul 2021 ~ Jul 2021
Jan 2018Aug 2026

Targeted Sectors

LogisticsHealthcareFinancialManufacturingMedicalInformation TechnologyMilitaryDefenseJournalistsAerospace

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.