Fox Kitten — APT Profile
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.Also tracked as
UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm
Tools & malware
- China Chopper Web Shell
- ngrok Tunneling Tool
- Pay2Key Ransomware
- PsExec Remote Execution
Vendor research
- How Microsoft names threat actors Microsoft
- Iran-Based Threat Actor Exploits VPN Vulnerabilities CISA AA
- Pay2Key Ransomware – A New Campaign by Fox Kitten ClearSky
- Fox Kitten – Widespread Iranian Espionage-Offensive Campaign ClearkSky Fox Kitten
- Dragos. (n.d.). PARISITE Dragos
- Who Is PIONEER KITTEN? Crowdstrike