Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Caracal Kitten

Also known as: APT-Q-58

Description

Caracal Kitten, also known as APT‑Q‑58, is a highly sophisticated threat actor whose primary focus is espionage. The group concentrates on activists associated with the Kurdistan Democratic Party (KDP), deploying mobile remote access trojans that masquerade as legitimate applications. By tricking users into installing these apps, Caracal Kitten gains persistent and privileged access to victims’ personal data and device information. The actor’s methodology relies heavily on social engineering tactics tailored for mobile platforms. Victims receive suspicious links or appear within app marketplaces where malware is embedded in seemingly benign utilities such as "CALENDAR," "Roboto," or the generic label "Trojan." Once installed, the malware establishes command‑and‑control (C2) channels through a large number of pseudo‑random domain names that exhibit a high degree of obfuscation. In addition to data exfiltration, Caracal Kitten carries out reconnaissance on device operating systems, harvesting credentials and identifying security software. The target sectors—non‑profit advocacy groups and media organizations—often house politically charged information, reflecting the actor’s strategic intent to acquire intelligence that can influence the political narrative surrounding Kurdish issues.

Goals & Targeting

Targeted Sectors

Non profit
Media

AI Analysis

Grounded in web research
· 3 days ago

Executive Summary

Caracal Kitten (APT‑Q‑58) is a state‑sponsored espionage actor that targets activists linked to the Kurdistan Democratic Party within non‑profit and media sectors. The group deploys malicious mobile applications masquerading as legitimate apps to install remote access trojans, enabling covert collection of personal data and device credentials. Their operations are driven by political intelligence objectives against opposition groups.

Goals & Targeting

Caracal Kitten seeks to build a comprehensive dossier on KDP activists by accessing personal communications, financial records, and social networks. The target profile focuses on low‑security environments such as non‑profits and media outlets where users are more likely to engage with mobile apps that carry political overtones. By infiltrating these groups, the actor aims to gather actionable intelligence for political manipulation or coercion.

Enhanced Description

Key Capabilities

  • Malicious mobile application development
  • Social engineering delivery via fake app distribution
  • Remote access trojan (RAT) persistence on Android/iOS devices
  • Credential harvesting and keylogging
  • Device information collection
  • Domain generation algorithm for C2 obfuscation
  • Use of fast‑flux style domain subdomains
  • Stealthy data exfiltration over HTTP/HTTPS or DNS

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Command and Control
Exfiltration

ATT&CK Techniques

T1110.001
T1133
T1071.002
T1059.003
T1105
T1566.001
T1547.021
T1124
T1018
T1082

Software / Tooling

CALENDAR (custom app bundle)
Roboto (Android library wrapper)
STOP (application framework)
Trojan (generic RAT payload)
Cursor (utility injector)
Custom Android RAT

Campaigns & Victims

The actor appears to operate on a sporadic but precise tempo, launching campaigns that coincide with significant KDP political events. Victims are typically individuals who have publicly engaged in advocacy or journalism regarding Kurdish affairs and use mobile devices for communication. Caracal Kitten’s campaign patterns include staged domain generation to evade detection, as well as use of legitimate app marketplaces for initial distribution, indicating a blend of technical skill and opportunistic social engineering.

IOC Patterns

  • Domain names with randomized subdomain strings (e.g., aqdrmf-rymPhb-ibnC6b.aqdrmf)
  • Malicious mobile application packages disguised as legitimate utilities
  • Spear‑phishing messages containing links to malicious app stores or direct downloads
  • Fast‑flux style domain provisioning for C2

Recommended Actions

  • Implement strict policy controls on installation of third‑party mobile applications, including whitelisting and verification processes.
  • Deploy mobile device management (MDM) solutions that enforce security configurations and monitor for data exfiltration streams.
  • Use threat intelligence feeds to block known malicious domains and employ DNS filtering to block dynamic domain registrations.
  • Conduct regular user awareness training focused on social engineering via mobile apps and phishing messages.
  • Encrypt sensitive data at rest and in transit, especially within mobile devices used by political activists.
  • Implement network segmentation to limit lateral movement from compromised mobile endpoints.
  • Enable anomaly detection for high‑volume outbound traffic and the use of uncommon protocols like DNS tunneling.

Suggested Tags

APT
Espionage
Mobile Malware
Political Targeting
Kurdistan Democratic Party
Non-Profit Sector
Media Sector

Confidence Assessment

The assessment is based on limited publicly available information, with no confirmed campaign attribution or detailed technical analysis in the current data set. The actor’s existence and objectives are supported by descriptions of malicious mobile RATs targeting KDP activists, but specifics such as exact tool versions, full technique mapping, or broader operational footprint remain uncertain.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. www.mandiant.com — Cited by web research for: CALENDAR

Intel Summary

10

Techniques

11

Tools

0

Campaigns

38

IOCs

0

Observed Data

7

Tactics

Tags

APT
Backdoor / C2
Espionage
Kurdistan Democratic Party
Nation-state sponsor
Mobile Malware
Political Targeting
Non-Profit Sector
Media Sector

Details

Type
Unknown
Primary Motivation
Espionage
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.