Threat Actor 🇮🇷 Iran
Tortoiseshell
Also known as: IMPERIAL KITTEN · Yellow Liderc · Imperial Kitten · TA456 · DUSTYCAVE · Crimson Sandstorm · Cuboid Sandstorm · Smoke Sandstorm · CURIUM
A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providers’ customers. The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access.
Indicators of Compromise 35
Domain aecert[.]org Domain buisness-centeral-transportation[.]com Domain business-deegital[.]azurewebsites[.]net Domain business-deegital[.]com Domain business-startup[.]azurewebsites[.]net Domain businessdeegital[.]azurewebsites[.]net Domain businessmixture[.]com Domain businessstartup[.]azurewebsites[.]net Domain global-reds[.]com Domain healthcarezoom-centeral[.]azurewebsites[.]net Domain healthcarezoomcenteral[.]azurewebsites[.]net Domain healthcarezoomcenteral[.]org Domain maadinglobal[.]com Domain neexportfolio[.]azurewebsites[.]net Domain neexportfolio[.]com Domain realhealthshop[.]com Domain smartconnect[.]azurewebsites[.]net Domain thehealth-life[.]com Domain tjconsultingservices[.]com Domain toadreport[.]azurewebsites[.]net Filename IPHLPAPI.dll Filename libwinpthread-1.dll Filename sspicli.dll Filename unbcl.dll MD5 42f847597109da2a220391bb09d00676 MD5 5fa15ef96808ea82f0a6176f0bb4b386 MD5 6038d42af0affd1fb263f470c0956f6b MD5 a239e655709a2518dd0b7bdbed163679 MD5 ae628efa305387b633dce82f9364875b MD5 afb1c1583606599c7272cfb33cc6f498 MD5 c832ecd135781b11f59e3fffb3d2b6ac MD5 c90f0efadbf322e5eb1c4103a38c30e6 MD5 d09b14a2fe01c7363ecc56f5d046162c MD5 f7d36cc5904a53252d2bb3d21615134f IP 172[.]86[.]98[.]113
MITRE ATT&CK TTPs 14
T1001.002 T1027 T1059.001 T1071 T1071.001 T1085 T1090 T1105 T1129 T1132.001 T1133 T1566 T1573 T1574.002
Steganography
Command And Control
Obfuscated Files or Information
Defense Evasion
PowerShell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
T1085
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Shared Modules
Execution
Standard Encoding
Command And Control
External Remote Services
Persistence
Phishing
Initial Access
Encrypted Channel
Command And Control
DLL Side-Loading
Persistence
Source Articles
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an APT group also known as UNC1549, is conducting cyber-espionage operations targeting aerospace, defense, telecommunications, and government sectors in the Middle East and Africa. The group uses spear-phishing and fake recruitment portals to deploy new malware tools, including NightLedger, a Windows backdoor that performs reconnaissance, command execution, and data exfiltration, and two WebSocket-based tunneling tools, BridgeHead and ArcBridge, which enable covert C2 communications and SOCKS5 tunneling through compromised hosts. The infrastructure includes domains hosted on Azure and Cloudflare, with targeting logic based on username checks to avoid execution in unintended environments.
securelist ·1mo ago
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Iranian state-backed threat actor Nimbus Manticore is conducting cyber espionage operations across the Middle East, Africa, and South Asia using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge. The group leverages phishing lures and fake videoconferencing pages to deliver payloads, which are executed via DLL side-loading. NightLedger enables reconnaissance, command execution, file operations, and screenshot capture, while BridgeHead and ArcBridge establish covert relay tunnels through victim systems for operator-controlled traffic.
hacker-news ·1mo ago