Domestic Kitten

Also known as: APT-C-50, Bouncing Golf, Domestic Kitten, DomesticKitten - APT-C-50

An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along with surrounding voice recordings. Researchers with CheckPoint discovered the attack and named it Domestic Kitten. The targets are Kurdish and Turkish natives, and ISIS supporters, all Iranian citizens.

๐ŸŒ Country Iran
๐Ÿ“… Activity 2018 โ€” 2018
๐Ÿงญ ATT&CK G0097
2018
2018

Introduction

An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along with surrounding voice recordings. Researchers with CheckPoint discovered the attack and named it Domestic Kitten. The targets are Kurdish and Turkish natives, and ISIS supporters, all Iranian citizens.

Activities and Tactics

Country of Origin: ๐Ÿ‡ฎ๐Ÿ‡ท Iran

First Seen: 2018

Last Activity: 2018

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 1 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • MobileOrder
  • Archelaus Beta

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Iran Additional attribution information pending cataloguing.

References

[1] mitre-attack [2] Trend Micro Bouncing Golf 2019 E. Xu, G. Guo. (2019, June 28). Mobile Cyberespionage Campaign โ€˜Bouncing Golfโ€™ Affects Middle East. Retrieved January 27, 2020.