Fox Kitten
Also known as: UNC757 · Parisite · Pioneer Kitten · RUBIDIUM · Lemon Sandstorm
Overview
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.
Naming & attribution
Fox Kitten is tracked under 6 names across the industry. It uses 41 documented ATT&CK techniques — more than 76% of the 174 groups tracked here. Activity attributed since at least 2017.
| Name | First reported by |
|---|---|
| UNC757 | CISA |
| Parisite | ClearSky |
| Pioneer Kitten | Orleans, A |
| RUBIDIUM | Microsoft |
| Lemon Sandstorm | Microsoft |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1213.005Messaging Applications — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Malware families with current indicators
2 families attributed to Fox Kitten, carrying 299 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- SystemBC 296 indicators
- Pay2Key 3 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 41 techniques across 11 tactics
Resource Development
-
T1585Establish Accounts -
T1585.001Social Media Accounts
Initial Access
Execution
-
T1053.005Scheduled Task -
T1059Command and Scripting Interpreter -
T1059.001PowerShell -
T1059.003Windows Command Shell
Persistence
-
T1136.001Local Account -
T1505.003Web Shell
Privilege Escalation
-
T1546.008Accessibility Features
Stealth
-
T1027.010Command Obfuscation -
T1027.013Encrypted/Encoded File -
T1036.004Masquerade Task or Service -
T1036.005Match Legitimate Resource Name or Location -
T1078Valid Accounts
Credential Access
-
T1003.001LSASS Memory -
T1003.003NTDS -
T1110Brute Force -
T1552.001Credentials In Files -
T1555.005Password Managers
Discovery
-
T1012Query Registry -
T1018Remote System Discovery -
T1046Network Service Discovery -
T1083File and Directory Discovery -
T1087.001Local Account -
T1087.002Domain Account -
T1217Browser Information Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares -
T1021.004SSH -
T1021.005VNC -
T1210Exploitation of Remote Services
Collection
-
T1005Data from Local System -
T1039Data from Network Shared Drive -
T1213.005Messaging Applications -
T1530Data from Cloud Storage -
T1560.001Archive via Utility
Command and Control
-
T1090Proxy -
T1102Web Service -
T1105Ingress Tool Transfer -
T1572Protocol Tunneling
Tools & malware (5)
China Chopper · Pay2Key · ngrok · PsExec · SystemBC