ATT&CKGroupsCopyKittens

CopyKittens

G0052

Threat group.View on attack.mitre.org

About this group

CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1059.001
PowerShell

CopyKittens has used PowerShell Empire.

T1090
Proxy

CopyKittens has used the AirVPN service for operational activity.

T1218.011
Rundll32

CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode.

T1553.002
Code Signing

CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared.

T1560.001
Archive via Utility

CopyKittens uses ZPP, a .NET console program, to compress files with ZIP.

T1560.003
Archive via Custom Method

CopyKittens encrypts data with a substitute cipher prior to exfiltration.

T1564.003
Hidden Window

CopyKittens has used -w hidden and -windowstyle hidden to conceal PowerShell windows.

T1588.002
Tool

CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities.

Software4

Campaigns0

None recorded.

References3

  1. ClearSky CopyKittens March 2017 Open source
    ClearSky Cyber Security. (2017, March 30). Jerusalem Post and other Israeli websites compromised by Iranian threat agent CopyKitten. Retrieved August 21, 2017.
  2. ClearSky Wilted Tulip July 2017 Open source
    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.
  3. CopyKittens Nov 2015 Open source
    Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.