CopyKittens
Overview
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.
Naming & attribution
CopyKittens is tracked under 1 names across the industry. It uses 8 documented ATT&CK techniques — more than 24% of the 174 groups tracked here. Activity attributed since at least 2013.
| Name | First reported by |
|---|---|
| CopyKittens | ClearSky Cyber Security |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- DarkHydrus — 3 shared techniques (25% overlap)
- APT19 China — 4 shared techniques (16% overlap)
- Blue Mockingbird — 4 shared techniques (15% overlap)
- Daggerfly China — 3 shared techniques (14% overlap)
- Gorgon Group Pakistan — 3 shared techniques (14% overlap)
- Cinnamon Tempest China — 3 shared techniques (13% overlap)
Targets
Civil society · Government · Private sector
Regions
Germany · Israel · Jordan · Saudi Arabia · United States
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 8 techniques across 6 tactics
Resource Development
-
T1588.002Tool
Execution
-
T1059.001PowerShell
Stealth
-
T1218.011Rundll32 -
T1564.003Hidden Window
Defense Impairment
-
T1553.002Code Signing
Collection
-
T1560.001Archive via Utility -
T1560.003Archive via Custom Method
Command and Control
-
T1090Proxy
Tools & malware (4)
Cobalt Strike · Empire · TDTESS · Matryoshka
Reporting (3)
- Operation Wilted Tulip: Exposing a cyber espionage apparatus — ClearSky Cyber Security and Trend Micro
- Jerusalem Post and other Israeli websites compromised by Iranian threat agent CopyKitten — ClearSky Cyber Security
- CopyKittens Attack Group — Minerva Labs LTD and ClearSky Cyber Security