CopyKittens

MITRE ATT&CK: G0052 View on attack.mitre.org

Aliases: Slayer Kitten, CopyKittens

First seen
2013-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 12:32:03

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:il country_code:sa country_code:tr country_code:us country_code:jo country_code:de

Context

CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.

Detection coverage

  • 156 YARA rules
  • 258 Sigma rules

Malware & tools used

  • Archive via Custom Method (attack-pattern)
  • Archive via Utility (attack-pattern)
  • PowerShell (attack-pattern)
  • Proxy (attack-pattern)
  • Rundll32 (attack-pattern)
  • Hidden Window (attack-pattern)
  • Tool (attack-pattern)
  • Code Signing (attack-pattern)
  • TDTESS (malware)
  • Matryoshka (malware)
  • Empire (malware)
  • Cobalt Strike (malware)

Reports & references

  • s3-eu-west-1.amazonaws.com — Copykittens (report)
  • domaintools.com — Case Study Hunting Campaign Indicators On Privacy Protected Attack Infrastr (report)
  • clearskysec.com — Copykitten Jpost (report)
  • clearskysec.com — Tulip (report)
  • cfr.org — Copykittens (report)
  • clearskysec.com — Operation Wilted Tulip (report)
  • MITRE ATT&CK — G0052 (report)
  • clearskysec.com — Operation Wilted Tulip (report)
  • cdn2.hubspot.net — Copykittens (report)

External references