Tortoiseshell Group

Threat Actor updated 10 months ago (2024-02-28T05:15:36.488Z)
Download STIX
Preview STIX
Not enough context has been learned about Tortoiseshell Group for a description yet. However we're tracking it as a Threat Actor profile. Threat Actor: A threat actor, also commonly referred to as a threat group, adversary, or hacking team, is a human entity that is behind the execution of actions with malicious intent. It could be a single person, a private company, or part of a government entity. The cybersecurity industry comes up with some pretty crazy naming conventions, and there are very little standards.
Description last updated:
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Unc1549 is a possible alias for Tortoiseshell Group. UNC1549, also known as Smoke Sandstorm and Tortoiseshell, is a suspected Iranian threat actor targeting the aerospace and defense sectors in the Middle East, specifically Israel and the United Arab Emirates. The group's activities have been discovered and tracked by Google Cloud’s Mandiant, who have
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Google
Phishing
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Tortoiseshell Threat Actor is associated with Tortoiseshell Group. Tortoiseshell is a prominent threat actor associated with multiple Iranian Advanced Persistent Threat (APT) groups, including MASN. It has been linked to a multi-year cyberattack campaign that targeted over a dozen US companies and government entities, including the Department of the Treasury. The cUnspecified
2
The Imperial Kitten Threat Actor is associated with Tortoiseshell Group. Imperial Kitten, also known as Tortoiseshell and UNC1549, is a significant threat actor identified by cybersecurity firms CrowdStrike and Mandiant. The group has been associated with various malicious activities, including the distribution of malware through SWC, and the use of IMAPLoader and other Unspecified
2
Source Document References
Information about the Tortoiseshell Group Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more