Names | Tortoiseshell (Symantec) Imperial Kitten (CrowdStrike) | |
Country | ![]() | |
Sponsor | State-sponsored | |
Motivation | Information theft and espionage | |
First seen | 2018 | |
Description | (Symantec) A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providers’ customers. The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access. | |
Observed | Sectors: Defense, IT, Maritime and Shipbuilding. Countries: Saudi Arabia, UAE, USA and Middle East. | |
Tools used | get-logon-history.ps1, Infostealer, liderc, SysKit. | |
Operations performed | Sep 2019 | Cisco Talos recently discovered a threat actor attempting to take advantage of Americans who may be seeking a job, especially military veterans. <https://blog.talosintelligence.com/2019/09/tortoiseshell-fake-veterans.html> |
Information | <https://www.symantec.com/blogs/threat-intelligence/tortoiseshell-apt-supply-chain> |
Last change to this card: 14 April 2020
Download this actor card in PDF or JSON format
Previous: Tonto Team, HartBeat, Karma Panda
Next: Transparent Tribe, APT 36
Thailand Computer Emergency Response Team (ThaiCERT) Follow us on![]() ![]() |
Report incidents |
|
![]() |
+66 (0)2-123-1234 | |
![]() |
report@thaicert.or.th | |
![]() |
Download PGP key |