CURIUM

G1012

Threat group.View on attack.mitre.org

About this group

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1005
Data from Local System

CURIUM has exfiltrated data from a compromised machine.

T1041
Exfiltration Over C2 Channel

CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

CURIUM has used SMTPS to exfiltrate collected data from victims.

T1059.001
PowerShell

CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments.

T1082
System Information Discovery

CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information.

T1124
System Time Discovery

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.

T1189
Drive-by Compromise

CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader.

T1204.002
Malicious File

CURIUM has lured users into opening malicious files delivered via social media.

T1505.003
Web Shell

CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks.

T1566.001
Spearphishing Attachment

CURIUM has used phishing with malicious attachments for initial access to victim environments.

T1566.003
Spearphishing via Service

CURIUM has used social media to deliver malicious files to victims.

T1583.001
Domains

CURIUM created domains to facilitate strategic website compromise and credential capture activities.

T1583.003
Virtual Private Server

CURIUM created virtual private server instances to facilitate use of malicious domains and other items.

T1583.004
Server

CURIUM has created dedicated servers for command and control and exfiltration purposes.

T1584.006
Web Services

CURIUM has compromised legitimate websites to enable strategic website compromise attacks.

View all 19 procedure examples

Software1

Campaigns0

None recorded.

References2

  1. Microsoft Iranian Threat Actor Trends November 2021 Open source
    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.
  2. Symantec Tortoiseshell 2019 Open source
    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.