Threat group.View on attack.mitre.org
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Fox Kitten has used prodump to dump credentials from LSASS. |
| T1003.003 NTDS |
Fox Kitten has used Volume Shadow Copy to access credential information from NTDS. |
| T1005 Data from Local System |
Fox Kitten has searched local system resources to access sensitive documents. |
| T1012 Query Registry |
Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat. |
| T1018 Remote System Discovery |
Fox Kitten has used Angry IP Scanner to detect remote systems. |
| T1021.001 Remote Desktop Protocol |
Fox Kitten has used RDP to log in and move laterally in the target environment. |
| T1021.002 SMB/Windows Admin Shares |
Fox Kitten has used valid accounts to access SMB shares. |
| T1021.004 SSH |
Fox Kitten has used the PuTTY and Plink tools for lateral movement. |
| T1021.005 VNC |
Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement. |
| T1027.010 Command Obfuscation |
Fox Kitten has base64 encoded scripts to avoid detection. |
| T1027.013 Encrypted/Encoded File |
Fox Kitten has base64 encoded payloads to avoid detection. |
| T1036.004 Masquerade Task or Service |
Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate. |
| T1039 Data from Network Shared Drive |
Fox Kitten has searched network shares to access sensitive documents. |
| T1046 Network Service Discovery |
Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.