Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Domestic Kitten

Also known as: Domestic Kitten, Bouncing Golf, APT-C-50

Description

An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along with surrounding voice recordings. Researchers with CheckPoint discovered the attack and named it Domestic Kitten. The targets are Kurdish and Turkish natives, and ISIS supporters, all Iranian citizens.

AI Analysis

· 1 week ago

Executive Summary

Domestic Kitten is a nation-state threat actor primarily involved in espionage activities targeting specific groups, including Kurds, Turks, ISIS supporters, and Iranians through malicious mobile applications.

Goals & Targeting

Domestic Kitten's strategic objective is to gather intelligence through targeted surveillance. They specifically target individuals linked to Kurdish and Turkish groups, ISIS supporters, and Iranian citizens, suggesting a focus on regional security concerns and potential adversarial relationships.

Enhanced Description

Domestic Kitten, also known as Bouncing Golf and APT-C-50, conducts surveillance against targeted individuals using malicious mobile apps. These apps collect sensitive information and voice recordings, indicating a high level of sophistication in their espionage tactics. The group's activities were first identified by CheckPoint researchers, highlighting its focus on geopolitical regions with significant security interests.

Key Capabilities

  • Development of malicious mobile applications
  • Surveillance capabilities including voice recording

MITRE ATT&CK Tactics

Espionage
Collection

ATT&CK Techniques

T1566.001 (OSINT Collection)
T1078 (Valid Accounts)

Software / Tooling

Custom mobile malware
C2 communication tools

Campaigns & Victims

Domestic Kitten's campaigns involve targeted phishing and social engineering tactics to distribute malicious apps. Their activities have been observed in regions with significant geopolitical tensions, indicating a pattern of surveillance aimed at specific national security interests.

IOC Patterns

  • Malicious mobile application distribution
  • Suspicious SMS or call activity from unknown numbers

Recommended Actions

  • Implement mobile device security policies
  • Monitor for unauthorized app installations
  • Educate users on phishing and social engineering threats

Suggested Tags

Nation-state actor
Espionage
Mobile malware
Geopolitical targets

Confidence Assessment

Moderately confident; while specific TTPs are identified, more details on their tools and techniques would enhance understanding. Limited historical data beyond CheckPoint's discovery is a gap.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Nation-state actor
Espionage
Mobile malware
Geopolitical targets

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.