ATT&CKGroupsFerocious Kitten

Ferocious Kitten

G0137

Threat group.View on attack.mitre.org

About this group

Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1036.002
Right-to-Left Override

Ferocious Kitten has used right-to-left override to reverse executables’ names to make them appear to have different file extensions, rather than their real ones.

T1036.005
Match Legitimate Resource Name or Location

Ferocious Kitten has named malicious files update.exe and loaded them into the compromise host's “Public” folder.

T1204.002
Malicious File

Ferocious Kitten has attempted to convince victims to enable malicious content within a spearphishing email by including an odd decoy message.

T1566.001
Spearphishing Attachment

Ferocious Kitten has conducted spearphishing campaigns containing malicious documents to lure victims to open the attachments.

T1583.001
Domains

Ferocious Kitten has acquired domains imitating legitimate sites.

T1588.002
Tool

Ferocious Kitten has obtained open source tools for its operations, including JsonCPP and Psiphon.

Software2

Campaigns0

None recorded.

References1

  1. Kaspersky Ferocious Kitten Jun 2021 Open source
    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.