Introduction
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015. Kaspersky Ferocious Kitten Jun 2021
Activities and Tactics
Country of Origin: 🇮🇷 Iran
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1204.002 Malicious File
- T1036.002 Right-to-Left Override
- T1036.005 Match Legitimate Resource Name or Location
- T1566.001 Spearphishing Attachment
- T1588.002 Tool
- T1583.001 Domains
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- Back Orifice
- Back Orifice 2000
- Virus RAT
- Sky Wyder
- Chrome Remote Desktop
- Archelaus Beta
- CrossRat
MITRE ATT&CK Software
Attribution and Evidence
Country of Origin: Iran Additional attribution information pending cataloguing.
References
[1] mitre-attack [2] Kaspersky Ferocious Kitten Jun 2021 GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.