Actors Insights|Latest update04/07/2026

Yellow Liderc

Named by PWCSuspected state sponsor: Islamic Republic of Iran

Yellow Liderc is PwC's designation for the Iranian threat cluster known as Imperial Kitten, named after the Liderc malware family — a custom .NET implant that uses IMAP email protocols for command and control. PwC documented Yellow Liderc conducting strategic web compromise operations targeting Israeli maritime and technology organizations, as well as direct phishing campaigns against defense-adjacent targets. The cluster's distinctive use of email-based C2 and focus on Israeli and Middle Eastern targets aligns precisely with CrowdStrike's Imperial Kitten and Symantec's Tortoiseshell tracking of the same IRGC-linked actor.

First Seen:Dec 2022
Last Seen:Jan 2026
Indexed Reports:1
Public IOCs:95
also known as:
Imperial Kitten (CrowdStrike)Yellow Liderc (PWC)TA456 (Proofpoint)DUSTYCAVECrimson Sandstorm (Microsoft)Cuboid Sandstorm (Microsoft)Smoke Sandstorm (Microsoft)CURIUM (Microsoft)Tortoiseshell (Symantec)G1012 (Mitre)

Targeted Regions

Europe
EU
Europe
Europe
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Middle East
ME
Middle East
Middle East
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
United States
US
United States
United States
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Jan 2022Nov 2026

Targeted Sectors

DefenseInformation TechnologyLogisticsAerospace

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.