Ferocious Kitten
Overview
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.
Naming & attribution
Ferocious Kitten is tracked under 1 names across the industry. It uses 6 documented ATT&CK techniques — more than 17% of the 174 groups tracked here. Activity attributed since at least 2015.
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- IndigoZebra China — 4 shared techniques (44% overlap)
- DarkHydrus — 3 shared techniques (30% overlap)
- BlackTech China — 4 shared techniques (25% overlap)
- Transparent Tribe Pakistan — 4 shared techniques (25% overlap)
- Whitefly — 3 shared techniques (25% overlap)
- BITTER — 4 shared techniques (22% overlap)
TTPs — 6 techniques across 4 tactics
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1204.002Malicious File
Stealth
-
T1036.002Right-to-Left Override -
T1036.005Match Legitimate Resource Name or Location
Tools & malware (2)
MarkiRAT · BITSAdmin