Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TRACER KITTEN

Description

In April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a telecommunications company in the Europe, Middle East and Africa (EMEA) region. The actor was found operating under valid user accounts, using custom backdoors in combination with SSH tunnels for C2. The adversary leveraged their foothold to conduct a variety of reconnaissance activities, undertake credential harvesting and prepare for data exfiltration.

AI Analysis

· 1 week ago

Executive Summary

TRACER KITTEN is an Iran-based adversary conducting malicious activities against telecommunications companies in the EMEA region. Using valid user accounts and custom backdoors with SSH tunnels, they compromise systems for reconnaissance, credential harvesting, and potential data exfiltration, posing significant risks to critical infrastructure.

Goals & Targeting

TRACER KITTEN likely targets the telecommunications sector to gain access to critical infrastructure, potentially for economic advantage, espionage, or strategic disruption. Their focus on EMEA regions may be linked to geopolitical interests or regional influence, aiming to gather sensitive information or disrupt services.

Enhanced Description

TRACER KITTEN was first identified by CrowStrike Falcon OverWatch in April 2020 targeting a telecommunications company across Europe, Middle East, and Africa. Operating under valid user credentials, the group employed custom backdoors and SSH tunnels for command and control (C2), enabling persistence and covert communication. Their activities included extensive reconnaissance, credential harvesting, and preparation for data exfiltration, indicating a capability to disrupt or compromise sensitive infrastructure. The use of custom tools suggests a degree of sophistication tailored to specific campaigns.

Key Capabilities

  • Custom backdoors
  • SSH tunnels for C2
  • Valid user account compromise
  • Credential harvesting
  • Network reconnaissance

MITRE ATT&CK Tactics

Initial Access
Credential Access
Discovery
Exfiltration
Persistence

ATT&CK Techniques

T1078
T1548.001
T1197
T1003
T1566

Software / Tooling

Custom SSH tunneling tools
Custom backdoor malware
Valid account access tools

Campaigns & Victims

TRACER KITTEN operates with a focus on long-term access and data gathering, targeting critical sectors. Campaigns likely involve prolonged presence to facilitate data exfiltration, suggesting state-sponsored activity. Notable for their blend of custom tools and persistence mechanisms, they pose risks to telecommunications globally.

IOC Patterns

  • Custom backdoor binaries
  • SSH tunnel anomalies
  • Unusual account activity
  • Lateral movement patterns

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical accounts
  • Monitor network traffic for SSH tunnel anomalies
  • Conduct regular system audits and update firmware/software
  • Enhance network segmentation to limit lateral movement

Suggested Tags

APT
Espionage
Critical Infrastructure
Telecommunications
Region-EMEA

Confidence Assessment

Confidence in TRACER KITTEN's existence is high, based on CrowStrike discovery. Limited details on exact TTPs and motivations create some uncertainty; could be linked to other APT groups without further intelligence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Backdoor / C2
Data Exfiltration
APT
Espionage
Critical Infrastructure
Telecommunications
Region-EMEA

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.