Home/Threat Actor/Imperial Kitten
Threat Actor

Imperial Kitten

imperial_kitten_tortoiseshell · iran · active since 2017

Imperial Kitten (Tortoiseshell / Crimson Sandstorm / Curium / Yellow Liderc / TA456 / G0099) is an Iran IRGC-aligned cyber- espionage cluster active since 2017 and consolidated under the Imperial Kitten name by CrowdStrike's November 2023 disclosure, responsible for sustained operations against Israeli, Saudi- Arabian, Gulf-state, US-defense-industrial-base, and increasingly Taiwanese and Indian targets, originating with the 2018-2019 Tortoiseshell campaign against Saudi IT service providers with probable supply-chain compromise tradecraft (Symantec September 2019 disclosure) and operationally most consequential for the sustained Marcella Flores fake-persona social-engineering operation against US aerospace and defense industrial base employees disclosed by Proofpoint in July 2021 (TA456 tracking), with a signature toolkit anchored on IMAPLoader, Liderc, Syskit, Lempo, and the newer POFF (Pacific Ocean Files) backdoor, and a defining operational tradecraft signature of elaborate fake- persona social-engineering across multi-year interaction histories.

iran confidence: high 20 aliases MITRE ATT&CK G1012 ↗

Profile

Imperial Kitten (also tracked as Tortoiseshell, Crimson Sandstorm, Curium, Yellow Liderc, TA456, and MITRE ATT&CK G0099) is an Iran- aligned cyber-espionage cluster active since at least 2017, widely assessed by vendor research consensus to operate on behalf of the Islamic Revolutionary Guard Corps (IRGC), with some vendor assessments specifically suggesting the IRGC's Intelligence Organization (IRGC-IO), the same Iranian intelligence service that also runs APT35 / Charming Kitten / Mint Sandstorm (already covered as apt35_charmingkitten.yaml). The cluster is operationally distinct from APT35 with a different victimology focus (Gulf-state IT supply-chain and US defense industrial base rather than dissident-and-influence operations), a different toolkit, and a different operational tradecraft signature (heavy fake-persona social-engineering). No formal US, UK, or EU government indictment of individual operators or front companies has been published for the cluster specifically.

the IRGC-aligned framing rests on vendor-research consensus and is not at the formal-state-indictment confidence tier of APT35 sub-cluster attributions or Pioneer Kitten's August 2024 OFAC designations. The cluster was first publicly disclosed under the "Tortoiseshell" name by Symantec in September 2019 ("Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks"), documenting sustained operations against multiple Saudi IT service providers and managed service providers with evidence of probable supply-chain compromise tradecraft aimed at reaching downstream Saudi customer networks. The MSP-style victim profile anticipated the broader trend toward MSP-supply-chain targeting that would subsequently characterize Cloud Hopper (APT10) and other publicly-tracked clusters. CrowdStrike's November 2023 "IMPERIAL KITTEN" consolidation unified the Tortoiseshell, TA456, Crimson Sandstorm, Yellow Liderc, and Curium vendor naming streams under a single cluster identity. The cluster's most operationally consequential publicly-documented campaign is the "Marcella Flores" persona disclosed by Proofpoint in July 2021 (Proofpoint TA456 tracking). The Marcella Flores persona, purporting to be an aerobics instructor from Liverpool , operated across multiple social-media platforms with a detailed back-story, photographs, and sustained multi-year interaction history with selected US aerospace and defense industrial base employees before eventual delivery of Lempo malware via fake YouTube-link social-engineering. The campaign is among the most operationally consequential publicly-documented Iran-aligned social-engineering operations and demonstrates the cluster's sustained investment in fake-persona tradecraft alongside conventional spear-phishing and watering-hole tradecraft. Operationally Imperial Kitten's toolkit centers on a portfolio of bespoke implants: IMAPLoader (a stealthy Windows backdoor using IMAP mailbox abuse as a C2 channel, distinctive among Iran-aligned clusters), Liderc (the cluster's older signature backdoor that gave the Yellow Liderc PwC tracking its name), Syskit (the Tortoiseshell-era C++ Windows implant), Lempo (the Marcella Flores delivery implant), POFF / Pacific Ocean Files (a newer 2022-2023 implant disclosed in CrowdStrike's November 2023 consolidation), and LiteHTTP. The cluster supplements the bespoke toolkit with extensive living-off-the-land tooling (PowerShell, mshta, rundll32, certutil) and open-source offensive-security tools (Mimikatz, Cobalt Strike, Impacket, PsExec, fast reverse proxy). Targeting focus has expanded across multiple regions and sectors over the cluster's operational lifetime: 2018-2019 Saudi IT service providers (Tortoiseshell era), 2020-2021 US defense industrial base (Marcella Flores / TA456 era), 2022-2023 Israeli transportation / logistics / healthcare / technology and continued Gulf-state operations (Imperial Kitten era), 2023-2024 Taiwanese technology and Indian defense-research expansion. The Israeli targeting profile aligns with broader IRGC geopolitical priorities and the historical Israel-Iran cyber-conflict dynamic; the US defense industrial base targeting aligns with longstanding Iranian state interest in US military capability development. A handful of operational notes: First, the cluster's vendor-naming proliferation (Imperial Kitten / Tortoiseshell / Crimson Sandstorm / Curium / Yellow Liderc / TA456 / Tortoise Team) reflects more than four years of fragmented pre- consolidation vendor tracking. Modern reporting should default to "Imperial Kitten" as the CrowdStrike-canonical name following the November 2023 consolidation.

"Tortoiseshell" remains the Symantec-canonical name and the original public cluster identifier. Second, the cluster is operationally and attribution-wise distinct from MOIS-aligned Iran clusters in this corpus, APT34 / OilRig (MOIS), APT39 / Chafer (MOIS), and MuddyWater (MOIS). The IRGC ↔ MOIS distinction reflects real differences in Iranian intelligence-service tasking and tradecraft and should not be collapsed. Third, attribution to IRGC specifically, though dominant in vendor reporting, has not been confirmed by formal US, UK, or EU government attribution. Treat the IRGC-tasking framing as high-confidence-by-vendor-consensus but not at the formal- indictment confidence tier of APT35 sub-cluster attributions or Pioneer Kitten's August 2024 OFAC designations.

Aliases

20
imperial kittenimperial_kittenimperialkittentortoiseshelltortoise shelltortoise_shellcrimson sandstormcrimson_sandstormcrimsonsandstormcuriumyellow lidercyellow_lidercyellowlidercta456ta_456tortoise teamtortoise_teamg0099atk 86atk86

Notable Campaigns

8
2024-2025Continued Operations (2024-2025)
2023-2024ITRI Taiwan and Asian Targeting Expansion (2023-2024)
2023CrowdStrike: IMPERIAL KITTEN Consolidation (November 2023)
2023Microsoft Crimson Sandstorm Renaming and Continued Tracking (2023)
2022-2023Israeli Transportation, Logistics, and Healthcare Targeting (2022-2023)
2020-2021Marcella Flores Persona / TA456, US Defense Industrial Base Targeting (Proofpoint, July 2021)
2019Symantec: Tortoiseshell Group Disclosure (September 18, 2019)
2018-2019Tortoiseshell, Saudi IT Service Provider Supply-Chain Targeting (2018-2019)

Attribution & Reporting

Attributed by
CrowdStrikeMicrosoftMicrosoft Threat Intelligence CenterSymantecProofpointMandiant / FireEyePwC Threat IntelligenceRecorded Future Insikt GroupCisco TalosClearSky Cyber SecurityESETSentinelOneKasperskyCybereasonVolexityPRODAFTGroup-IBCluster25Cyfirma
Key reporting
reportSymantec: Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks (September 18, 2019), seminal cluster disclosure
reportCybereason: Tortoiseshell Creates Fake Veteran Hiring Website to Host Malware (September 2019)
reportClearSky Cyber Security: Operation Quicksand, MuddyWater's Offensive Attack Against Israeli Organizations (March 2020), adjacent Iran-aligned context
reportProofpoint: I Knew You Were Trouble, TA456 Targets Defense Contractor with Alluring Social Media Persona (July 28, 2021), Marcella Flores disclosure
reportProofpoint: TA456 Tracking (multiple years, 2020-2023)
reportMandiant: UNC788, Iran-Aligned Cyber Targeting of Aerospace and Energy Sectors
reportPwC Threat Intelligence: Yellow Liderc Tracking
reportCrowdStrike: IMPERIAL KITTEN Deploys Novel Malware Families in Middle East-Focused Operations (November 2023), seminal cluster consolidation
reportMicrosoft: Threat Actor Naming Taxonomy, Crimson Sandstorm (April 2023)
reportSekoia: Imperial Kitten Iran Tracking (2023-2024)
reportRecorded Future Insikt Group: Imperial Kitten Iran Targeting (multiple years)
reportSentinelOne Labs: Adjacent Middle East Cluster Tracking
reportCluster25: Imperial Kitten / Tortoiseshell Operational Profile
reportCyfirma: Tortoiseshell Iran Tracking (multiple years)
reportMalpedia Actor Profile: Tortoiseshell
reportMITRE ATT&CK Group G0099, Tortoiseshell

Operational

State sponsor

Iran, Islamic Revolutionary Guard Corps (IRGC). Attribution to IRGC is widely accepted across vendor research consensus (CrowdStrike, Microsoft, Symantec, Mandiant, Proofpoint, PwC, Recorded Future, Cisco Talos, ClearSky, ESET, and others), with some vendor assessments specifically suggesting the IRGC's Intelligence Organization (IRGC-IO), the same Iranian intelligence service that also runs APT35 / Charming Kitten / Mint Sandstorm (already covered as apt35_charmingkitten.yaml). The cluster is operationally distinct from APT35 with a different victimology focus (Gulf-state IT supply-chain and US defense industrial base rather than dissident-and-influence operations), a different toolkit (Liderc/IMAPLoader, Syskit, Lempo, LiteHTTP, Pacific Ocean Files backdoor rather than the POWERSTAR/CharmPower ecosystem), and a different operational tradecraft signature (heavy social-engineering with elaborate fake personas including the "Marcella Flores" persona disclosed by Proofpoint in 2021).

The cluster is operationally and attribution-wise distinct from the MOIS-aligned Iran clusters in this corpus, APT34 / OilRig, APT39 / Chafer, MuddyWater (all already covered). No formal US, UK, or EU government indictment of individual operators or front companies has been published for Imperial Kitten / Tortoiseshell specifically (in contrast to the named-individual indictments and OFAC designations covering APT35 sub-clusters and the Pioneer Kitten cluster). The IRGC-aligned framing should be treated as high-confidence by vendor-research consensus standards but is not at the formal-state-indictment confidence tier of APT35 or Pioneer Kitten.

Motivations
espionage, intelligence_gathering, geopolitical_collection, defense_industrial_collection, supply_chain_compromise, gulf_state_intelligence, israeli_intelligence, influence_operations
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MARCELLA FLORES PERSONA INFRASTRUCTUREMSHTASYS KITSYSKIT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin