CURIUM
MITREUnknown
Unknown
Unknown
[CURIUM](https://attack.mitre.org/groups/G1012) is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East.(Citation: Symantec Tortoiseshell 2019) [CURIUM](https://attack.mitre.org/groups/G1012) has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note [CURIUM](https://attack.mitre.org/groups/G1012) has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.(Citation: Microsoft Iranian Threat Actor Trends November 2021)
Tecniche Utilizzate (19)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1005 | Data from Local System | - |
| T1041 | Exfiltration Over C2 Channel | - |
| T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | - |
| T1059.001 | PowerShell | - |
| T1082 | System Information Discovery | - |
| T1124 | System Time Discovery | - |
| T1189 | Drive-by Compromise | - |
| T1204.002 | Malicious File | - |
| T1505.003 | Web Shell | - |
| T1566.001 | Spearphishing Attachment | - |
| T1566.003 | Spearphishing via Service | - |
| T1583.001 | Domains | - |
| T1583.003 | Virtual Private Server | - |
| T1583.004 | Server | - |
| T1584.006 | Web Services | - |
Alias (784)
Malware Utilizzato (1)
Metadata
| ID: | 906 |
| Created: | 13/01/2026 17:48 |
| Updated: | 21/04/2026 16:00 |