CopyKittens
MITRE ATT&CK: G0052 View on attack.mitre.org
Aliases: Slayer Kitten, CopyKittens
- First seen
- 2013-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 12:32:03
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Targeted regions: country_code:il country_code:sa country_code:tr country_code:us country_code:jo country_code:de
Context
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.
Detection coverage
- 156 YARA rules
- 258 Sigma rules
Malware & tools used
- Archive via Custom Method (attack-pattern)
- Archive via Utility (attack-pattern)
- PowerShell (attack-pattern)
- Proxy (attack-pattern)
- Rundll32 (attack-pattern)
- Hidden Window (attack-pattern)
- Tool (attack-pattern)
- Code Signing (attack-pattern)
- TDTESS (malware)
- Matryoshka (malware)
- Empire (malware)
- Cobalt Strike (malware)
Reports & references
- s3-eu-west-1.amazonaws.com — Copykittens (report)
- domaintools.com — Case Study Hunting Campaign Indicators On Privacy Protected Attack Infrastr (report)
- clearskysec.com — Copykitten Jpost (report)
- clearskysec.com — Tulip (report)
- cfr.org — Copykittens (report)
- clearskysec.com — Operation Wilted Tulip (report)
- MITRE ATT&CK — G0052 (report)
- clearskysec.com — Operation Wilted Tulip (report)
- cdn2.hubspot.net — Copykittens (report)