Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RedKitten

Also known as: APT34, Helix Kitten, APT35, Newscaster, Cobalt Gypsy, Refined Kitten, Elfin, Static Kitten, tracked as, Archer RAT, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Parastoo, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, Royal Ransomware

Description

RedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The malware utilizes GitHub and Google Drive for configuration and payload retrieval, while employing Telegram for command and control. Although precise attribution is challenging, the activity exhibits TTPs associated with Iranian state-sponsored actors and linguistic indicators suggest a Farsi-speaking threat actor. RedKitten is characterized as an AI-accelerated campaign exploiting the humanitarian crisis surrounding Iran’s Dey 1404 protests.

Goals & Targeting

Targeted Sectors

Government
Non profit
Financial services
Defense
Education
Telecommunications
Critical infrastructure
Healthcare
Energy
Manufacturing
Media
Retail
Information technology
Hospitality
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation
Oil gas

Targeted Countries / Regions

IR
US
CN
RU
IL
IN
UA
GB
AE
PK
DE
BY
KP
SA
PL
TW
CA
AU
IQ
SY

AI Analysis

· 1 week ago

Executive Summary

RedKitten is an emerging threat actor targeting NGOs and individuals documenting human rights abuses in Iran. The campaign utilizes AI-accelerated malware distributed via GitHub and Google Drive, with Telegram as a command and control channel.

Goals & Targeting

RedKitten appears to focus on political or governmental targets within Iran, potentially aiming to disrupt activities related to the protests and suppress information flowing from the region. The targeting of NGOs indicates a strategic interest in limiting international awareness of human rights concerns.

Enhanced Description

RedKitten has been observed since January 2026, focusing on Iranian interests through campaigns leveraging public platforms for malicious activities. The group's use of AI suggests a sophisticated approach to developing malware, possibly aimed at enhancing attack efficiency. By exploiting the context of Iran’s Dey 1404 protests, RedKitten likely seeks to target individuals and groups involved in documenting human rights issues.

Key Capabilities

  • Command and Control (C2) via Telegram
  • Use of public platforms like GitHub and Google Drive for malware distribution
  • AI-accelerated malware development capabilities
  • Targeted attacks against specific demographics based on political context

MITRE ATT&CK Tactics

Cyber Espionage

Software / Tooling

Telegram
GitHub
Google Drive

Campaigns & Victims

RedKitten's campaigns suggest a focus on persistent, targeted operations against Iran-centric targets. The group’s use of AI and public platforms indicates a strategic approach to maintaining operational stealth while enhancing attack efficacy.

IOC Patterns

  • Spear-phishing emails with malicious links to GitHub or Google Drive
  • Command and control communications via Telegram
  • Data exfiltration through public file-sharing services
  • Social engineering tactics tied to ongoing political events in Iran

Recommended Actions

  • Monitor for phishing emails related to Iranian protests or NGOs
  • Implement AI-based detection tools to counter RedKitten's capabilities
  • Blocks access to Telegram C2 channels if possible
  • Enhance training on recognizing malicious links from public platforms
  • Regularly audit GitHub and Google Drive accounts for unauthorized activity

Suggested Tags

APT
Espionage
Political/Military
Phishing

Confidence Assessment

Low confidence in direct attribution but moderate confidence in the group's existence based on observed TTPs. More data is needed to confirm exact affiliations and specific techniques used.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 3 Email Address 7 Filename 5 Domain 5

References

  1. unit42.paloaltonetworks.com — Cited by web research for: APT34
  2. www.group-ib.com — Cited by web research for: Archer RAT
  3. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  4. www.rescana.com — Cited by web research for: WhatsApp
  5. www.trellix.com — Cited by web research for: curl
  6. www.proofpoint.com — Cited by web research for: Oil Gas

Intel Summary

29

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

APT
Backdoor / C2
Hacktivism
Espionage
Political/Military
Phishing

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.