Fox Kitten — APT Profile
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm
IntelFusions coverage (1)
- Spies and ransomware crews exploit the same edge devices 2026-08-26 · Vulnerabilities
Tools & malware
- China Chopper Web Shell
- ngrok Tunneling Tool
- Pay2Key Ransomware
- PsExec Remote Execution
Vendor research
- How Microsoft names threat actors Microsoft
- Iran-Based Threat Actor Exploits VPN Vulnerabilities CISA AA
- Pay2Key Ransomware – A New Campaign by Fox Kitten ClearSky
- Fox Kitten – Widespread Iranian Espionage-Offensive Campaign ClearkSky Fox Kitten
- Dragos. (n.d.). PARISITE Dragos
- Who Is PIONEER KITTEN? Crowdstrike
Countries linked to this actor
- Iran origin
- Azerbaijan targets