FurBall

Malware type
spyware
Profile updated
2026-07-07 12:54:38

Targeted industries: government-and-public-sector

Targeted regions: country_code:ir

Context

According to Check Point, they uncovered an operation dubbed "Domestic Kitten", which uses malicious Android applications to steal sensitive personal information from its victims: screenshots, messages, call logs, surrounding voice recordings, and more. This operation managed to remain under the radar for a long time, as the associated files were not attributed to a known malware family and were only detected by a handful of security vendors.

Reports & references

  • bleepingcomputer.com — Domestic Kitten Apt Operates In Silence Since 2016 (report)
  • Trend Micro — Mobile Cyberespionage Campaign Bouncing Golf Affects Middle East (report)
  • research.checkpoint.com — Domestic Kitten An Inside Look At The Iranian Surveillance Operations (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Furball (report)
  • bleepingcomputer.com — Hacking Group Updates Furball Android Spyware To Evade Detection (report)
  • virusbulletin.com — Domestic Kitten Iranian Surveillance Program (report)
  • ti.qianxin.com — Surprised By Cyrus The Great Disclosure Against Iran Cyrus Attack (report)
  • Trend Micro — Appendix Mobile Cyberespionage Campaign Bouncing Golf Affects Middle East (report)

External references