Tortoiseshell
Named by SymantecSuspected state sponsor: Islamic Republic of IranTortoiseshell is Symantec's designation for the Iranian threat cluster known as Imperial Kitten, active since at least 2018. The group targets IT managed service providers (MSPs) and supply chain companies to gain downstream access to defense and government networks in the Middle East and the United States. Symantec documented campaigns in which Tortoiseshell compromised IT firms serving Saudi Arabian defense contractors, using custom malware including Sartoruis and Backdoor.Dituran for persistence and data collection. The cluster shares IRGC attribution and targeting patterns with the broader Imperial Kitten, TA456, and Crimson Sandstorm identities.
Targeted Regions
IsraelIsrael
May 2022 ~ May 2023
May 2022 ~ May 2023
May 2022 ~ May 2023
May 2022 ~ May 2023
Saudi ArabiaSaudi Arabia
Jul 2018 ~ Sep 2019
Jul 2018 ~ Sep 2019
Jul 2018 ~ Sep 2019
Jul 2018 ~ Sep 2019
United KingdomUnited Kingdom
Jul 2021 ~ Jul 2021
United StatesUnited States
Sep 2019 ~ Sep 2019
Jul 2021 ~ Jul 2021
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.