Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Tortoiseshell, Imperial Kitten, TA456, Curium, Marcella Flores, Houseblend, Crimson Sandstorm, Cuboid Sandstorm, Yellow Liderc, Devious Serpens, Cobalt Fireside, DEV-0228, IMPERIAL KITTEN, DUSTYCAVE, Smoke Sandstorm, CURIUM, Tortoise Shell
A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providers’ customers. The group, which we are calling Tortoiseshell, has been active since at least July 2018. Symantec has identified a total of 11 organizations hit by the group, the majority of which are based in Saudi Arabia. In at least two organizations, evidence suggests that the attackers gained domain admin-level access. Overlap has been found with Magic Hound’s Subgroup: TA455, Smoke Sandstorm .
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database