Also known as: APT-Q-58
Caracal Kitten, also known as APT‑Q‑58, is a highly sophisticated threat actor whose primary focus is espionage. The group concentrates on activists associated with the Kurdistan Democratic Party (KDP), deploying mobile remote access trojans that masquerade as legitimate applications. By tricking users into installing these apps, Caracal Kitten gains persistent and privileged access to victims’ personal data and device information. The actor’s methodology relies heavily on social engineering tactics tailored for mobile platforms. Victims receive suspicious links or appear within app marketplaces where malware is embedded in seemingly benign utilities such as "CALENDAR," "Roboto," or the generic label "Trojan." Once installed, the malware establishes command‑and‑control (C2) channels through a large number of pseudo‑random domain names that exhibit a high degree of obfuscation. In addition to data exfiltration, Caracal Kitten carries out reconnaissance on device operating systems, harvesting credentials and identifying security software. The target sectors—non‑profit advocacy groups and media organizations—often house politically charged information, reflecting the actor’s strategic intent to acquire intelligence that can influence the political narrative surrounding Kurdish issues.
Targeted Sectors
Executive Summary
Caracal Kitten (APT‑Q‑58) is a state‑sponsored espionage actor that targets activists linked to the Kurdistan Democratic Party within non‑profit and media sectors. The group deploys malicious mobile applications masquerading as legitimate apps to install remote access trojans, enabling covert collection of personal data and device credentials. Their operations are driven by political intelligence objectives against opposition groups.
Goals & Targeting
Caracal Kitten seeks to build a comprehensive dossier on KDP activists by accessing personal communications, financial records, and social networks. The target profile focuses on low‑security environments such as non‑profits and media outlets where users are more likely to engage with mobile apps that carry political overtones. By infiltrating these groups, the actor aims to gather actionable intelligence for political manipulation or coercion.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actor appears to operate on a sporadic but precise tempo, launching campaigns that coincide with significant KDP political events. Victims are typically individuals who have publicly engaged in advocacy or journalism regarding Kurdish affairs and use mobile devices for communication. Caracal Kitten’s campaign patterns include staged domain generation to evade detection, as well as use of legitimate app marketplaces for initial distribution, indicating a blend of technical skill and opportunistic social engineering.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on limited publicly available information, with no confirmed campaign attribution or detailed technical analysis in the current data set. The actor’s existence and objectives are supported by descriptions of malicious mobile RATs targeting KDP activists, but specifics such as exact tool versions, full technique mapping, or broader operational footprint remain uncertain.
No campaigns linked yet.
No observed data linked yet.
10
Techniques
11
Tools
0
Campaigns
38
IOCs
0
Observed Data
7
Tactics