National Cyber Warfare Foundation (NCWF)

Tortoiseshell


0 user ratings
2024-07-26 20:08:28
blscott

 - archive -- 
A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providersa customers.
The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access.
Alternate Group Names
Crimson SandstormDUSTYCAVEIMPERIAL KITTENImperial KittenTA456Yellow Liderc

Alternative Names
FunRun RATLidercCURIUMTortoise ShellDEV-0228UNC1549Crimson SandstormSmoke SandstormCuboid SandstormYellow LidercTA456APT35ImperialKittenImperial KittenG1012



Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.