Threat group.View on attack.mitre.org
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.
| Technique | Procedure example |
|---|---|
| T1036.002 Right-to-Left Override |
Ferocious Kitten has used right-to-left override to reverse executables’ names to make them appear to have different file extensions, rather than their real ones. |
| T1036.005 Match Legitimate Resource Name or Location |
Ferocious Kitten has named malicious files |
| T1204.002 Malicious File |
Ferocious Kitten has attempted to convince victims to enable malicious content within a spearphishing email by including an odd decoy message. |
| T1566.001 Spearphishing Attachment |
Ferocious Kitten has conducted spearphishing campaigns containing malicious documents to lure victims to open the attachments. |
| T1583.001 Domains |
Ferocious Kitten has acquired domains imitating legitimate sites. |
| T1588.002 Tool |
Ferocious Kitten has obtained open source tools for its operations, including JsonCPP and Psiphon. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.