Yellow Liderc
Named by PWCSuspected state sponsor: Islamic Republic of IranYellow Liderc is PwC's designation for the Iranian threat cluster known as Imperial Kitten, named after the Liderc malware family — a custom .NET implant that uses IMAP email protocols for command and control. PwC documented Yellow Liderc conducting strategic web compromise operations targeting Israeli maritime and technology organizations, as well as direct phishing campaigns against defense-adjacent targets. The cluster's distinctive use of email-based C2 and focus on Israeli and Middle Eastern targets aligns precisely with CrowdStrike's Imperial Kitten and Symantec's Tortoiseshell tracking of the same IRGC-linked actor.
Targeted Regions
EuropeEurope
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Middle EastMiddle East
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
United StatesUnited States
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Dec 2022 ~ Oct 2023
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.