LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1012: CURIUM

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East.[1] CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.[2]

EnterpriseG1012GroupObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

CURIUM matters because the ATT&CK record describes a patient social-engineering operation, not just commodity malware delivery. The group is reported to build trust with targets over months through social media, benign file exchanges, and later malware delivery, with historical targeting of Middle East IT service providers. For leaders, the practical issue is whether security controls, user reporting paths, and incident response playbooks can handle slow-burn relationship abuse that may occur outside normal email channels.

Executive priority

Prioritize CURIUM-relevant readiness where trusted relationships, IT service provider access, or third-party communications could affect business continuity. Executives should ask whether the organization can evidence controls for social media/service-based phishing, attachment handling, web-exposed server persistence, command-and-control exfiltration, and Windows malware investigation, especially where managed service or supply-chain relationships create concentrated risk.

Technical view

ATT&CK does not provide detection text for this group, so validation should be relationship-driven. SOC and IR teams should map coverage across the related behaviors: resource development using domains, VPS/server infrastructure, web services, social media accounts, and email accounts; initial access through spearphishing attachments, spearphishing via service, malicious files, and drive-by compromise; execution via PowerShell and user-opened files; persistence through web shells; discovery of system information and time; collection from local systems; and exfiltration over C2 or encrypted non-C2 protocols. IMAPLoader is listed as .NET-based malware associated with CURIUM operations since at least 2022 and using email protocols for command and control and payload delivery, so Windows endpoint, email-protocol, and network telemetry are especially important where that software is in scope.

Likely telemetry

  • Email security logs for attachments, links, sender reputation, mailbox access, and delivery events
  • Logs or alerts from third-party messaging, collaboration, and social media access where monitored or reported by users
  • Endpoint process telemetry, especially PowerShell execution, script activity, .NET execution, and user-launched files
  • Windows endpoint detection data relevant to IMAPLoader investigation
  • Network telemetry for C2-like sessions, encrypted non-C2 exfiltration patterns, DNS, proxy, and egress connections

Detection direction

  • Do not rely only on enterprise email controls; the ATT&CK relationships include spearphishing via third-party services and social media account preparation, which may bypass normal mail gateways.
  • Tune detections for sequences rather than single events: long-running persona contact, benign file exchange, later attachment/link delivery, user execution, PowerShell, discovery, collection, and exfiltration.
  • Validate PowerShell visibility and logging quality before assuming coverage for T1059.001-related execution.
  • For IMAPLoader-relevant hunts, confirm visibility into Windows endpoint activity and email-protocol network usage; the supplied relationship states the malware uses email protocols for C2 and payload delivery.
  • Review web-facing server monitoring for web shell indicators, including unexpected script files, unusual web requests, and command execution patterns, while accounting for legitimate administrative scripts.

Mitigation priorities

  • Start with exposure and process controls for social engineering: user reporting channels, executive and high-risk user awareness, and procedures for suspicious social media or third-party service contact.
  • Harden attachment and link handling across email and collaboration workflows, including detonation, policy enforcement, and rapid removal processes where available.
  • Restrict and monitor PowerShell use according to administrative need, with logging sufficient for investigation.
  • Strengthen egress monitoring and control for unusual email-protocol, C2-like, and encrypted outbound traffic, especially from endpoints that should not communicate that way.
  • Improve web server hygiene and monitoring to reduce web shell persistence risk: patching, least privilege, file integrity monitoring, and review of exposed services.
Additional notes and limits

This take is based on ATT&CK group G1012, its aliases, official description, external references, and listed relationships. The most decision-relevant theme is patient trust-building before malware delivery, supported by related techniques for persona/account preparation, phishing through email and services, malicious files, web shells, discovery, collection, and exfiltration. IMAPLoader is the only related software provided and is described as Windows .NET-based malware associated with CURIUM operations since at least 2022.

The group object has no official detection text, no group-level platforms, and no group-level tactics specified. Related techniques provide behavioral context but do not prove those behaviors are present in any specific environment. Local telemetry, business geography, third-party relationships, user populations, and incident evidence are required before making exposure, attribution, or coverage claims.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

CURIUM

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East.[1] CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.[2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

19 rows
DomainIDNameRelationship / procedure
EnterpriseT1566.003Spearphishing via ServiceSub-technique

CURIUM has used social media to deliver malicious files to victims.[2]

EnterpriseT1505.003Web ShellSub-technique

CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks.[1]

EnterpriseT1204.002Malicious FileSub-technique

CURIUM has lured users into opening malicious files delivered via social media.[2]

EnterpriseT1584.006Web ServicesSub-technique

CURIUM has compromised legitimate websites to enable strategic website compromise attacks.[3]

EnterpriseT1583.003Virtual Private ServerSub-technique

CURIUM created virtual private server instances to facilitate use of malicious domains and other items.[3]

EnterpriseT1082System Information Discovery

CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information.[1]

EnterpriseT1608.004Drive-by TargetSub-technique

CURIUM used strategic website compromise to fingerprint then target victims.[3]

EnterpriseT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolSub-technique

CURIUM has used SMTPS to exfiltrate collected data from victims.[3]

EnterpriseT1005Data from Local System

CURIUM has exfiltrated data from a compromised machine.[2]

EnterpriseT1585.001Social Media AccountsSub-technique

CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman.[2]

EnterpriseT1585.002Email AccountsSub-technique

CURIUM has created dedicated email accounts for use with tools such as IMAPLoader.[3]

EnterpriseT1124System Time Discovery

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.[3]

EnterpriseT1598.003Spearphishing LinkSub-technique

CURIUM used malicious links to adversary-controlled resources for credential harvesting.[3]

EnterpriseT1189Drive-by Compromise

CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader.[3]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

CURIUM has used phishing with malicious attachments for initial access to victim environments.[3]

EnterpriseT1059.001PowerShellSub-technique

CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments.[1]

EnterpriseT1583.001DomainsSub-technique

CURIUM created domains to facilitate strategic website compromise and credential capture activities.[3]

EnterpriseT1041Exfiltration Over C2 Channel

CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.[3]

EnterpriseT1583.004ServerSub-technique

CURIUM has created dedicated servers for command and control and exfiltration purposes.[3]

Associated objects

Groups, software, and campaigns

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
3821fc6cc53cba83...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.0Current bundle3821fc6cc53c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  2. [2]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  3. [3]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  4. [4]
    Crimson Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  5. [5]
    Crimson Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  6. [6]
    Crimson Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  7. [7]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  8. [8]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  9. [9]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  10. [10]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  11. [11]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  12. [12]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  13. [13]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  14. [14]
    Proofpoint TA456 Defense Contractor July 2021

    Miller, J. et. al. (2021, July 28). I Knew You Were Trouble: TA456 Targets Defense Contractor with Alluring Social Media Persona. Retrieved March 11, 2024.

    Open source URL
  15. [15]
    Proofpoint TA456 Defense Contractor July 2021

    Miller, J. et. al. (2021, July 28). I Knew You Were Trouble: TA456 Targets Defense Contractor with Alluring Social Media Persona. Retrieved March 11, 2024.

    Open source URL
  16. [16]
    Proofpoint TA456 Defense Contractor July 2021

    Miller, J. et. al. (2021, July 28). I Knew You Were Trouble: TA456 Targets Defense Contractor with Alluring Social Media Persona. Retrieved March 11, 2024.

    Open source URL
  17. [17]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  18. [18]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  19. [19]
    TA456

    (Citation: Microsoft Threat Actor Naming July 2023)(Citation: Proofpoint TA456 Defense Contractor July 2021)

  20. [20]
    TA456

    (Citation: Microsoft Threat Actor Naming July 2023)(Citation: Proofpoint TA456 Defense Contractor July 2021)

  21. [21]
    TA456

    (Citation: Microsoft Threat Actor Naming July 2023)(Citation: Proofpoint TA456 Defense Contractor July 2021)

  22. [22]
    Tortoise Shell

    (Citation: Microsoft Threat Actor Naming July 2023)

  23. [23]
    Tortoise Shell

    (Citation: Microsoft Threat Actor Naming July 2023)

  24. [24]
    Tortoise Shell

    (Citation: Microsoft Threat Actor Naming July 2023)

  25. [25]
    Yellow Liderc

    (Citation: PWC Yellow Liderc 2023)

  26. [26]
    Yellow Liderc

    (Citation: PWC Yellow Liderc 2023)

  27. [27]
    Yellow Liderc

    (Citation: PWC Yellow Liderc 2023)

  28. [28]
    mitre-attackG1012
    Open source URL
  29. [29]
    mitre-attackG1012
    Open source URL
  30. [30]
    mitre-attackG1012
    Open source URL
  31. [31]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  32. [32]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  33. [33]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  34. [34]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  35. [35]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  36. [36]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  37. [37]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  38. [38]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  39. [39]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  40. [40]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  41. [41]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  42. [42]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  43. [43]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  44. [44]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  45. [45]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  46. [46]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  47. [47]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  48. [48]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  49. [49]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  50. [50]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  51. [51]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  52. [52]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  53. [53]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  54. [54]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  55. [55]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  56. [56]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  57. [57]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  58. [58]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  59. [59]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  60. [60]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  61. [61]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  62. [62]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  63. [63]
    Symantec Tortoiseshell 2019

    Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

    Open source URL
  64. [64]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  65. [65]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  66. [66]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.