Actors Insights|Latest update04/07/2026

Imperial Kitten

Named by CrowdStrikeSuspected state sponsor: Islamic Republic of Iran

Imperial Kitten is an IRGC-linked Iranian threat cluster active since at least 2017, named by CrowdStrike. The group conducts espionage and strategic web compromise operations primarily targeting Israeli and Middle Eastern organizations in the transportation, logistics, maritime, defense, and technology sectors. It is characterized by job-recruitment phishing, SQL injection, stolen VPN credential abuse, and distinctive email-based (IMAP) command and control using malware families including IMAPLoader and Liderc. The cluster is also tracked as Tortoiseshell, TA456, Crimson Sandstorm, and Curium across the industry.

First Seen:Nov 2020
Last Seen:Jan 2026
Indexed Reports:2
Public IOCs:76
Cluster: Imperial KittenMisp: Bohrium
also known as:
Smoke Sandstorm (Microsoft)BOHRIUM (Microsoft)Imperial Kitten (CrowdStrike)

Targeted Regions

Israel
IL
Israel
Israel
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Mar 2022 ~ Nov 2023
Nov 2020 ~ Nov 2025
Mar 2022 ~ Nov 2023
Nov 2020 ~ Nov 2025
Mar 2022 ~ Nov 2023
Nov 2020 ~ Nov 2025
Mar 2022 ~ Nov 2023
Nov 2020 ~ Nov 2025
Mar 2022 ~ Nov 2023
Nov 2020 ~ Nov 2025
Mar 2022 ~ Nov 2023
Nov 2020 ~ Nov 2025
Mar 2022 ~ Nov 2023
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Nov 2020 ~ Nov 2025
Middle East
ME
Middle East
Middle East
Mar 2022 ~ Nov 2023
Mar 2022 ~ Nov 2023
Mar 2022 ~ Nov 2023
Mar 2022 ~ Nov 2023
Mar 2022 ~ Nov 2023
Mar 2022 ~ Nov 2023
Mar 2022 ~ Nov 2023
Jan 2020Sep 2026

Targeted Sectors

LogisticsMilitaryInformation TechnologyTransportation

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.