Tortoiseshell (IMPERIAL KITTEN) is an Iran-nexus threat actor known for supply chain attacks.
Analyst brief
Tortoiseshell (also tracked as IMPERIAL KITTEN) is an Iran-linked nation-state threat actor active since at least 2018. The group targets IT providers and sectors like defense, government, energy, and healthcare mainly in the Middle East, Europe, and the US, using supply chain attacks to compromise downstream customers. Its key TTPs include Spearphishing Link, Drive-by Compromise, PowerShell, Web Shells, custom malware such as IMAPLoader, and exfiltration over C2 channels. Defenders should focus on supply chain compromise detection, monitoring for anomalous PowerShell and web shells, and scrutinizing C2 traffic and VPS/Web Services infrastructure usage.
Tortoiseshell
IMPERIAL KITTENYellow LidercImperial Kitten
nation-state
A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providers’ customers.
The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access.
origin (suspected)
🇮🇷Iran· state-sponsoredattribution confidence: medium (50)
Monitor network traffic and unusual data transfers to mitigate Exfiltration Over C2 Channel and Exfiltration Over Asymmetric Encrypted Non-C2 Protocol techniques.
FAQ2
Which geographic regions does the Tortoiseshell group primarily target?+
The group primarily targets organizations in the Middle East, Europe, and the US.
What is an example of custom malware used by Tortoiseshell?+
IMAPLoader is an example of custom malware used by this actor.