Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CopyKittens

Also known as: Slayer Kitten, DarkHydrus, LazyMeerkat, G0052, tracked as, Fox Kitten, Pioneer Kitten, the threat actor, Plaid Rain, including OneDrive, for data exfiltration, command, control, Lyceum

Description

CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.(Citation: ClearSky CopyKittens March 2017)(Citation: ClearSky Wilted Tulip July 2017)(Citation: CopyKittens Nov 2015)

Goals & Targeting

Targeted Sectors

Education
Research
Government
Defense
Media
Financial services
Manufacturing
Non profit
Energy
Aviation
Legal services
Healthcare
Information technology
Transportation
Food agriculture
Critical infrastructure

Targeted Countries / Regions

US
DE
IL
SA
middle_east
IR
TR
LB
EG
UA

AI Analysis

· 1 week ago

Executive Summary

CopyKittens is an Iranian cyber espionage group active since at least 2013, targeting governments, educational institutions, and research organizations in the U.S., Germany, Israel, and the Middle East. The group is linked to the 'Wilted Tulip' campaign, leveraging sophisticated techniques and tools like Cobalt Strike for infiltration and data exfiltration. Its operations suggest a focus on intelligence gathering for geopolitical advantage.

Goals & Targeting

CopyKittens' primary motivation is espionage, targeting sectors and regions with access to sensitive political, military, and scientific information. By focusing on government agencies, educational institutions, and research organizations, the group aims to extract classified data, geopolitical intelligence, and technological advancements that could provide strategic advantages to Iran. The actor’s targeting of the U.S., Germany, and Middle Eastern nations suggests a focus on Western and regional rivals, particularly those involved in defense, energy, and academic sectors. This pattern aligns with Iran’s historical interest in intelligence collection to counter perceived threats and support national interests.

Enhanced Description

CopyKittens, also known as Slayer Kitten, DarkHydrus, LazyMeerkat, and G0052, is a threat actor attributed to Iran with a primary focus on cyber espionage. Since 2013, the group has conducted targeted attacks against entities in Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany, with a particular emphasis on sectors involving government operations, academic research, and institutional knowledge. The group's activities were notably documented in the 2017 'Wilted Tulip' campaign, which involved advanced persistent threat (APT) tactics and the deployment of custom malware. Linked tools include TDTESS, Matryoshka, and Cobalt Strike, reflecting a blend of off-the-shelf and bespoke capabilities. The actor’s technical approach includes leveraging PowerShell, proxy infrastructure, and code-signing techniques to evade detection and maintain long-term access to compromised systems. Security researchers have tied CopyKittens to multiple campaigns exploiting human-operable vulnerabilities, such as spear-phishing, suggesting a combination of technical sophistication and social engineering in their operations.

Key Capabilities

  • Use of Cobalt Strike for command-and-control and lateral movement
  • Deployment of custom malware (e.g., TDTESS, Matryoshka)
  • Exploitation of PowerShell and Rundll32 for payload execution
  • Employment of proxy infrastructure to obfuscate network traffic
  • Code-signing techniques to evade detection by security systems
  • Spear-phishing with malicious documents to gain initial access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement

ATT&CK Techniques

T1560.001: Archive via Utility
T1218.011: Rundll32
T1560.003: Archive via Custom Method
T1553.002: Code Signing
T1090: Proxy
T1059.001: PowerShell
T1588.002: Tool
T1564.003: Hidden Window

Software / Tooling

TDTESS
Matryoshka
Cobalt Strike

Campaigns & Victims

CopyKittens has demonstrated a persistent operational tempo since at least 2013, with campaigns such as 'Wilted Tulip' highlighting their focus on spear-phishing and the use of multi-layered malware to maintain access to critical infrastructure. The group’s campaigns often target victims in the education and research sectors, leveraging their access to academic and technological resources. Notable operations include the use of custom backdoors and staged infrastructure hosted on bulletproof services, suggesting a preference for operational anonymity and the ability to adapt to changing cybersecurity defenses.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux techniques
  • Staging infrastructure on bulletproof hosting services
  • PowerShell-based command execution
  • Code-signing of malicious payloads to bypass security checks

Recommended Actions

  • Implement advanced email filtering to detect and block phishing attempts with macro-laced documents
  • Monitor for PowerShell and Rundll32-based execution patterns as indicators of compromise
  • Deploy endpoint detection and response (EDR) solutions to identify lateral movement and persistence mechanisms
  • Conduct regular red-team exercises to simulate attacks using techniques associated with CopyKittens
  • Use network traffic analysis tools to detect proxy infrastructure and anomalous DNS activity

Suggested Tags

APT
espionage
iran-related
government-sector
research-sector
education-sector
wilted-tulip

Confidence Assessment

The confidence level in the data is moderate to high, supported by multiple citation sources including ClearSky’s analysis of the 'Wilted Tulip' campaign and links to confirmed tools and techniques. However, gaps exist in understanding the full extent of the group’s infrastructure, potential ties to other Iranian APTs, and the specific geopolitical objectives behind certain operations. Further analysis of network traffic and IoCs from recent campaigns would improve confidence.

ATT&CK Techniques

Initial Access
1 technique

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 3 IPv4 Address 7 Domain 7 URL 1 Email Address 1 Filename 1

References

  1. ClearSky Wilted Tulip July 2017 — ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.
  2. ClearSky CopyKittens March 2017 — ClearSky Cyber Security. (2017, March 30). Jerusalem Post and other Israeli websites compromised by Iranian threat agent CopyKitten. Retrieved August 21, 2017.
  3. CopyKittens Nov 2015 — Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.
  4. www.microsoft.com — Cited by web research for: Plaid Rain
  5. attack.mitre.org — Cited by web research for: T1059
  6. attack.mitre.org — Cited by web research for: T1187
  7. www.huntress.com — Cited by web research for: Global
  8. apt.etda.or.th — Cited by web research for: Matryoshka RAT
  9. unit42.paloaltonetworks.com — Cited by web research for: Spear-phishing

Intel Summary

24

Techniques

56

Tools

1

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

APT
espionage
iran-related
government-sector
research-sector
education-sector
wilted-tulip

Details

MITRE ID
G0052
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--dcd81c6e-ebf7-4a16-93e0-9a97fa49c88a
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.