NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Fox Kitten

Fox Kitten

G0117 Iran MITRE ATT&CK →

Also known as: UNC757 · Parisite · Pioneer Kitten · RUBIDIUM · Lemon Sandstorm

Overview

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 41 techniques across 11 tactics

Resource Development

Initial Access

Persistence

Privilege Escalation

Credential Access

Lateral Movement

Command and Control

Tools & malware (5)

China Chopper · Pay2Key · ngrok · PsExec · SystemBC

Reporting (3)