Fox Kitten

Last Updated

Also known as: Fox Kitten, Lemon Sandstorm, Parisite, PARISITE, Pay2key, Pay2Key, Pioneer Kitten, PIONEER KITTEN, PioneerKitten, RUBIDIUM, UNC757

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering. ClearkSky Fox Kitten February 2020 CrowdStrike PIONEER KITTEN August 2020 Dragos PARISITE ClearSky Pay2Kitten December 2020

🌍 Country Iran
📝 Last Updated
🧭 ATT&CK G0117

Introduction

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering. ClearkSky Fox Kitten February 2020 CrowdStrike PIONEER KITTEN August 2020 Dragos PARISITE ClearSky Pay2Kitten December 2020

Activities and Tactics

Country of Origin: 🇮🇷 Iran

Notable Campaigns

  • Pay2Key

Tactics, Techniques, and Procedures (TTPs)

Ransomware Vulnerability Matrix observations

Category Vendor Product CVEs
Group Profile, Network Edge Check Point Security Gateway CVE-2024-24919
Group Profile, Virtualization Citrix NetScaler ADC & Gateway CVE-2023-3519
Group Profile, Virtualization Citrix NetScaler ADC & Gateway & SD-WAN CVE-2019-19781
Group Profile, Network Edge F5 BIG-IP CVE-2022-1388
Group Profile, Network Edge Palo Alto Networks PAN-OS Firewall CVE-2024-3400
Group Profile, Network Edge Pulse Secure / Ivanti Pulse Connect Secure CVE-2019-11510
Group Profile, Network Edge Pulse Secure / Ivanti Pulse Connect Secure CVE-2024-21887
Group Profile, Network Edge Pulse Secure / Ivanti Pulse Connect Secure & Pulse Policy Secure CVE-2019-11539

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • SSHNET:
  • Juicy Potato:
  • Port:
  • STSRCHECK:
  • LPManager:
  • Invoke-SMBClient:
  • Invoke-SMBEnum:
  • Invoke-SMBExec:
  • Invoke-TheHash:
  • Invoke-WMIExec:
  • SOCKET-Based Backdoor:
  • Ngrok:
  • Pay2Key ransomware:
  • FRPC:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Iran Additional attribution information pending cataloguing.

References

[1] mitre-attack [7] CISA AA20-259A Iran-Based Actor September 2020 CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020. [8] ClearSky Pay2Kitten December 2020 ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020. [9] ClearkSky Fox Kitten February 2020 ClearSky. (2020, February 16). Fox Kitten – Widespread Iranian Espionage-Offensive Campaign. Retrieved December 21, 2020. [10] Dragos PARISITE Dragos. (n.d.). PARISITE. Retrieved December 21, 2020. [11] Microsoft Threat Actor Naming July 2023 Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023. [12] CrowdStrike PIONEER KITTEN August 2020 Orleans, A. (2020, August 31). Who Is PIONEER KITTEN?. Retrieved December 21, 2020.