Also known as: APT34, Helix Kitten, APT35, Newscaster, Cobalt Gypsy, Refined Kitten, Elfin, Static Kitten, tracked as, Archer RAT, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Parastoo, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, Royal Ransomware
RedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The malware utilizes GitHub and Google Drive for configuration and payload retrieval, while employing Telegram for command and control. Although precise attribution is challenging, the activity exhibits TTPs associated with Iranian state-sponsored actors and linguistic indicators suggest a Farsi-speaking threat actor. RedKitten is characterized as an AI-accelerated campaign exploiting the humanitarian crisis surrounding Iran’s Dey 1404 protests.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
RedKitten is an emerging threat actor targeting NGOs and individuals documenting human rights abuses in Iran. The campaign utilizes AI-accelerated malware distributed via GitHub and Google Drive, with Telegram as a command and control channel.
Goals & Targeting
RedKitten appears to focus on political or governmental targets within Iran, potentially aiming to disrupt activities related to the protests and suppress information flowing from the region. The targeting of NGOs indicates a strategic interest in limiting international awareness of human rights concerns.
Enhanced Description
RedKitten has been observed since January 2026, focusing on Iranian interests through campaigns leveraging public platforms for malicious activities. The group's use of AI suggests a sophisticated approach to developing malware, possibly aimed at enhancing attack efficiency. By exploiting the context of Iran’s Dey 1404 protests, RedKitten likely seeks to target individuals and groups involved in documenting human rights issues.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
RedKitten's campaigns suggest a focus on persistent, targeted operations against Iran-centric targets. The group’s use of AI and public platforms indicates a strategic approach to maintaining operational stealth while enhancing attack efficacy.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in direct attribution but moderate confidence in the group's existence based on observed TTPs. More data is needed to confirm exact affiliations and specific techniques used.
No campaigns linked yet.
No observed data linked yet.
29
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics