In April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a telecommunications company in the Europe, Middle East and Africa (EMEA) region. The actor was found operating under valid user accounts, using custom backdoors in combination with SSH tunnels for C2. The adversary leveraged their foothold to conduct a variety of reconnaissance activities, undertake credential harvesting and prepare for data exfiltration.
Executive Summary
TRACER KITTEN is an Iran-based adversary conducting malicious activities against telecommunications companies in the EMEA region. Using valid user accounts and custom backdoors with SSH tunnels, they compromise systems for reconnaissance, credential harvesting, and potential data exfiltration, posing significant risks to critical infrastructure.
Goals & Targeting
TRACER KITTEN likely targets the telecommunications sector to gain access to critical infrastructure, potentially for economic advantage, espionage, or strategic disruption. Their focus on EMEA regions may be linked to geopolitical interests or regional influence, aiming to gather sensitive information or disrupt services.
Enhanced Description
TRACER KITTEN was first identified by CrowStrike Falcon OverWatch in April 2020 targeting a telecommunications company across Europe, Middle East, and Africa. Operating under valid user credentials, the group employed custom backdoors and SSH tunnels for command and control (C2), enabling persistence and covert communication. Their activities included extensive reconnaissance, credential harvesting, and preparation for data exfiltration, indicating a capability to disrupt or compromise sensitive infrastructure. The use of custom tools suggests a degree of sophistication tailored to specific campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TRACER KITTEN operates with a focus on long-term access and data gathering, targeting critical sectors. Campaigns likely involve prolonged presence to facilitate data exfiltration, suggesting state-sponsored activity. Notable for their blend of custom tools and persistence mechanisms, they pose risks to telecommunications globally.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in TRACER KITTEN's existence is high, based on CrowStrike discovery. Limited details on exact TTPs and motivations create some uncertainty; could be linked to other APT groups without further intelligence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics