APTTrail: crimson sandstorm indicators and references

Fecha
18 Jun 2026
Actor
crimson-sandstorm
Tipo
Ioc
Pais
Unknown
Sector
Software
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
crimson-sandstormActor
UnknownPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a crimson sandstorm. Aliases observados: crimson sandstorm, imperial kitten, ta456, yellow liderc. Conteo por tipo: domain: 185, url: 4.

Key Points

  • https://blog.talosintelligence.com/2019/09/tortoiseshell-fake-veterans.html
  • https://otx.alienvault.com/pulse/5d8201965473b98dbf01a84f
  • https://otx.alienvault.com/pulse/5d8a3103b8713b840f1b13dd
  • https://otx.alienvault.com/pulse/60f07dd74b222a6b9cc38975
  • https://www.symantec.com/blogs/threat-intelligence/tortoiseshell-apt-supply-chain

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a crimson sandstorm. Aliases observados: crimson sandstorm, imperial kitten, ta456, yellow liderc. Conteo por tipo: domain: 185, url: 4.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domain1st-smtp2go.emailAPTTrail
Domain2nd-smtp2go.emailAPTTrail
Domain3rd-smtp2go.emailAPTTrail
Domain4th-smtp2go.emailAPTTrail
Domainaccounts.camAPTTrail
Domainactivesessions.meAPTTrail
Domainadobes.softwareAPTTrail
Domainalhds.netAPTTrail
Domainapppure.cfAPTTrail
Domainbahri.siteAPTTrail
Domainbbcnews.emailAPTTrail
Domainbitly.camAPTTrail
Domainbiturl.cxAPTTrail
Domainbrdcst.emailAPTTrail
Domaincareeronestop.siteAPTTrail
Domaincc-security-inc.emailAPTTrail
Domainccsecurity-mail-inc.emailAPTTrail
Domainccsecurity-mail-inc.servicesAPTTrail
Domaincitymyworkday.comAPTTrail
Domaincityofberkeley.supportAPTTrail
Domaincnbcnews.emailAPTTrail
Domaincnnnews.globalAPTTrail
Domaincodejquery-ui.comAPTTrail
Domaincom-account-challenge.emailAPTTrail
Domaincom-signin-v2.emailAPTTrail
Domaincomlogin.onlineAPTTrail
Domaincomlogin.servicesAPTTrail
Domaincopyleft.todayAPTTrail
Domaincrisiswatchsupport.shopAPTTrail
Domaindatacatch.xyzAPTTrail

Referencias

Diamond Model

Adversary
crimson-sandstorm
Ver perfil →
Victim
APTTrail: crimson sandstorm indicators and references
Capability
Ioc
Infrastructure
1st-smtp2go.email
2nd-smtp2go.email
3rd-smtp2go.email
4th-smtp2go.email

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain 1st-smtp2go.email APTTrail VT OffSec SOCRadar
Domain 2nd-smtp2go.email APTTrail VT OffSec SOCRadar
Domain 3rd-smtp2go.email APTTrail VT OffSec SOCRadar
Domain 4th-smtp2go.email APTTrail VT OffSec SOCRadar
Domain accounts.cam APTTrail VT OffSec SOCRadar
Domain activesessions.me APTTrail VT OffSec SOCRadar
Domain adobes.software APTTrail VT OffSec SOCRadar
Domain alhds.net APTTrail VT OffSec SOCRadar
Domain apppure.cf APTTrail VT OffSec SOCRadar
Domain bahri.site APTTrail VT OffSec SOCRadar
Domain bbcnews.email APTTrail VT OffSec SOCRadar
Domain bitly.cam APTTrail VT OffSec SOCRadar
Domain biturl.cx APTTrail VT OffSec SOCRadar
Domain brdcst.email APTTrail VT OffSec SOCRadar
Domain careeronestop.site APTTrail VT OffSec SOCRadar
Domain cc-security-inc.email APTTrail VT OffSec SOCRadar
Domain ccsecurity-mail-inc.email APTTrail VT OffSec SOCRadar
Domain ccsecurity-mail-inc.services APTTrail VT OffSec SOCRadar
Domain citymyworkday.com APTTrail VT OffSec SOCRadar
Domain cityofberkeley.support APTTrail VT OffSec SOCRadar
Domain cnbcnews.email APTTrail VT OffSec SOCRadar
Domain cnnnews.global APTTrail VT OffSec SOCRadar
Domain codejquery-ui.com APTTrail VT OffSec SOCRadar
Domain com-account-challenge.email APTTrail VT OffSec SOCRadar
Domain com-signin-v2.email APTTrail VT OffSec SOCRadar
Domain comlogin.online APTTrail VT OffSec SOCRadar
Domain comlogin.services APTTrail VT OffSec SOCRadar
Domain copyleft.today APTTrail VT OffSec SOCRadar
Domain crisiswatchsupport.shop APTTrail VT OffSec SOCRadar
Domain datacatch.xyz APTTrail VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor crimson-sandstorm en el blog → Ver crimson-sandstorm en IntelTracker → URL IntelTracker: blog.talosintelligence.com→ URL IntelTracker: otx.alienvault.com→ URL IntelTracker: otx.alienvault.com→ URL IntelTracker: otx.alienvault.com→ URL IntelTracker: www.symantec.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: blog.talosintelligence.com→ Fuente OSINT: otx.alienvault.com→ Fuente OSINT: otx.alienvault.com→ Fuente OSINT: otx.alienvault.com → Buscar crimson-sandstorm en APTTrail → Repositorio APTTrail → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes