Also known as: Slayer Kitten, DarkHydrus, LazyMeerkat, G0052, tracked as, Fox Kitten, Pioneer Kitten, the threat actor, Plaid Rain, including OneDrive, for data exfiltration, command, control, Lyceum
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.(Citation: ClearSky CopyKittens March 2017)(Citation: ClearSky Wilted Tulip July 2017)(Citation: CopyKittens Nov 2015)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CopyKittens is an Iranian cyber espionage group active since at least 2013, targeting governments, educational institutions, and research organizations in the U.S., Germany, Israel, and the Middle East. The group is linked to the 'Wilted Tulip' campaign, leveraging sophisticated techniques and tools like Cobalt Strike for infiltration and data exfiltration. Its operations suggest a focus on intelligence gathering for geopolitical advantage.
Goals & Targeting
CopyKittens' primary motivation is espionage, targeting sectors and regions with access to sensitive political, military, and scientific information. By focusing on government agencies, educational institutions, and research organizations, the group aims to extract classified data, geopolitical intelligence, and technological advancements that could provide strategic advantages to Iran. The actor’s targeting of the U.S., Germany, and Middle Eastern nations suggests a focus on Western and regional rivals, particularly those involved in defense, energy, and academic sectors. This pattern aligns with Iran’s historical interest in intelligence collection to counter perceived threats and support national interests.
Enhanced Description
CopyKittens, also known as Slayer Kitten, DarkHydrus, LazyMeerkat, and G0052, is a threat actor attributed to Iran with a primary focus on cyber espionage. Since 2013, the group has conducted targeted attacks against entities in Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany, with a particular emphasis on sectors involving government operations, academic research, and institutional knowledge. The group's activities were notably documented in the 2017 'Wilted Tulip' campaign, which involved advanced persistent threat (APT) tactics and the deployment of custom malware. Linked tools include TDTESS, Matryoshka, and Cobalt Strike, reflecting a blend of off-the-shelf and bespoke capabilities. The actor’s technical approach includes leveraging PowerShell, proxy infrastructure, and code-signing techniques to evade detection and maintain long-term access to compromised systems. Security researchers have tied CopyKittens to multiple campaigns exploiting human-operable vulnerabilities, such as spear-phishing, suggesting a combination of technical sophistication and social engineering in their operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CopyKittens has demonstrated a persistent operational tempo since at least 2013, with campaigns such as 'Wilted Tulip' highlighting their focus on spear-phishing and the use of multi-layered malware to maintain access to critical infrastructure. The group’s campaigns often target victims in the education and research sectors, leveraging their access to academic and technological resources. Notable operations include the use of custom backdoors and staged infrastructure hosted on bulletproof services, suggesting a preference for operational anonymity and the ability to adapt to changing cybersecurity defenses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the data is moderate to high, supported by multiple citation sources including ClearSky’s analysis of the 'Wilted Tulip' campaign and links to confirmed tools and techniques. However, gaps exist in understanding the full extent of the group’s infrastructure, potential ties to other Iranian APTs, and the specific geopolitical objectives behind certain operations. Further analysis of network traffic and IoCs from recent campaigns would improve confidence.
Wilted Tulip
No observed data linked yet.
24
Techniques
56
Tools
1
Campaigns
40
IOCs
0
Observed Data
9
Tactics