The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access.
Alternate Group Names
Crimson Sandstorm, DUSTYCAVE, IMPERIAL KITTEN, Imperial Kitten, TA456, Yellow Liderc,
Alternative Names
FunRun RAT, Liderc, CURIUM, Tortoise Shell, DEV-0228, UNC1549, Crimson Sandstorm, Smoke Sandstorm, Cuboid Sandstorm, Yellow Liderc, TA456, APT35, ImperialKitten, Imperial Kitten, G1012,