Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ferocious Kitten

Description

Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.(Citation: Kaspersky Ferocious Kitten Jun 2021)

AI Analysis

· 1 week ago

Executive Summary

Ferocious Kitten is a cyber threat group primarily targeting Persian-speaking individuals in Iran since at least 2015. The group has demonstrated persistence over time, focusing on discreetly gathering information and maintaining operational security. Their activities align with data collection and espionage objectives, making them a significant concern for organizations and individuals within their target demographic.

Goals & Targeting

Ferocious Kitten's strategic objectives likely include intelligence collection and surveillance, targeting individuals and entities in Iran that could provide sensitive information. Their focus on Persians speaking indicates a regional or cultural specificity in their operations. The group's victims appear to be concentrated in Iran, implying a potential state-backed operation or a highly targeted criminal endeavor focused on discreetly gathering information.

Enhanced Description

Ferocious Kitten is a cyber threat actor that has been active since at least 2015, with primary operations targeting Persian-speaking populations in Iran. The group's activities have been linked to various malicious software tools and attack techniques, including the use of MarkiRAT malware. Ferocious Kitten's tactics are designed to remain elusive, leveraging TTPs such as right-to-left override (RLO) attacks and domain name abuse to avoid detection. The group's focus on Persian-speaking individuals suggests a potential emphasis on surveillance or espionage within Iran.

Key Capabilities

  • Use of MarkiRAT malware
  • Right-to-left (RLO) text spoofing attacks
  • Domain name abuse for command and control
  • Spear-phishing via malicious files

MITRE ATT&CK Tactics

Collection
Impact
Disruption

ATT&CK Techniques

T1036.005
T1204.002
T1583.001
T1588.002
T1566.001

Software / Tooling

MarkiRAT

Campaigns & Victims

Ferocious Kitten has conducted persistent campaigns targeting Persian-speaking individuals in Iran since at least 2015. Their operations are characterized by their use of RLO attacks and MarkiRAT malware, suggesting a focus on long-term intelligence gathering. Despite their longevity, little is known about their specific campaigns or victims beyond their primary geographic focus.

IOC Patterns

  • Spear-phishing with attachments
  • Malicious file downloads
  • Right-to-left (RLO) override attacks
  • Abuse of legitimate domain names
  • C2 communications via compromised domains

Recommended Actions

  • Implement RTO detection mechanisms to identify RLO attacks.
  • Monitor for suspicious activity using known MarkiRAT indicators.
  • Enhance user training on identifying phishing attempts and RTO spoofing.
  • Conduct regular network monitoring for unusual file downloads or domain usage.
  • Apply multi-factor authentication (MFA) where possible.

Suggested Tags

APT
espionage
Iran
malware

Confidence Assessment

Moderate confidence in Ferocious Kitten's targeting demographics and known tools, such as MarkiRAT. Additional information is needed on their specific motivations, additional campaigns beyond what has been linked, and other toolsets they may employ. The group's limited public exposure introduces some uncertainty regarding their full capabilities.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 17 URL 1 IPv4 Address 2

References

  1. Kaspersky Ferocious Kitten Jun 2021 — GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

Intel Summary

6

Techniques

1

Tools

0

Campaigns

59

IOCs

0

Observed Data

4

Tactics

Tags

APT
espionage
Iran
malware

Details

MITRE ID
G0137
Type
Unknown
Country of Origin
I
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--6566aac9-dad8-4332-ae73-20c23bad7f02
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.