Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
Pioneer Kitten
ID: 2c33573ab7ab103797e1526dc0ee21e320330
Cybercrime
State-Sponsored
Threat types: Intrusion, Exploitation, Espionage
Progress: 38%
Completeness: 33%
Freshness: 50%
Operation zone: —
Aliases
Limited alias preview
| Fox Kitten | — | — | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering. Ref: https://attack.mitre.org/groups/G0117/
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1003.001 | LSASS Memory | TA0006 |
|
| T1003.003 | NTDS | TA0006 |
|
| T1021.001 | Remote Desktop Protocol | TA0008 |
|
| T1021.002 | SMB/Windows Admin Shares | TA0008 |
|
| T1021.004 | SSH | TA0008 |
|
| T1021.005 | VNC | TA0008 |
|
| T1027.010 | Command Obfuscation | TA0005 |
|
| T1027.013 | Encrypted/Encoded File | TA0005 |
|
| T1036.004 | Masquerade Task or Service | TA0005 |
|
| T1036.005 | Match Legitimate Resource Name or Location | TA0005 |
|
| T1053.005 | Scheduled Task | TA0002 TA0003 TA0004 |
|
| T1059.001 | PowerShell | TA0002 |
|
| T1059.003 | Windows Command Shell | TA0002 |
|
| T1087.001 | Local Account | TA0007 |
|
| T1087.002 | Domain Account | TA0007 |
|
| T1136.001 | Local Account | TA0003 |
|
| T1213.005 | Messaging Applications | TA0009 |
|
| T1505.003 | Web Shell | TA0003 |
|
| T1546.008 | Accessibility Features | TA0003 TA0004 |
|
| T1552.001 | Credentials In Files | TA0006 |
|
| T1555.005 | Password Managers | TA0006 |
|
| T1560.001 | Archive via Utility | TA0009 |
|
| T1585.001 | Social Media Accounts | TA0042 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.