Fox Kitten
MITRE ATT&CK: G0117 View on attack.mitre.org
Aliases: UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm, PIONEER KITTEN, PARISITE, Fox Kitten, PioneerKitten
- First seen
- 2017-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:33:11
Targeted industries: energy-and-utilities technology-and-telecommunications government-and-public-sector defense-and-aerospace healthcare-and-pharmaceutical manufacturing
Targeted regions: country_code:ae country_code:sa country_code:au country_code:us country_code:de country_code:fr country_code:gb
Context
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.
Detection coverage
- 7 YARA rules
- 940 Sigma rules
Malware & tools used
- Data from Cloud Storage (attack-pattern)
- Remote System Discovery (attack-pattern)
- Brute Force (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Local Account (attack-pattern)
- Archive via Utility (attack-pattern)
- Command Obfuscation (attack-pattern)
- Data from Local System (attack-pattern)
- Establish Accounts (attack-pattern)
- VNC (attack-pattern)
- Credentials In Files (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Messaging Applications (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Password Managers (attack-pattern)
- NTDS (attack-pattern)
- Local Account (attack-pattern)
- Domain Account (attack-pattern)
- SSH (attack-pattern)
- Web Shell (attack-pattern)
- Scheduled Task (attack-pattern)
- Masquerade Task or Service (attack-pattern)
Reports & references
- youtu.be — Pbdu8Egwrc4 (report)
- dragos.com — Parisite (report)
- dragos.com — The Ics Threat Landscape (report)
- dragos.com — Na El Threat Perspective 2019 (report)
- clearskysec.com — Clearsky Fox Kitten Campaign (report)
- zdnet.com — Fbi Says An Iranian Hacking Group Is Attacking F5 Networking Devices (report)
- CrowdStrike — Who Is Pioneer Kitten (report)
- zdnet.com — Iranian Hackers Are Selling Access To Compromised Companies On An Underground Forum (report)
- CISA — Aa20 259A (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G0117 (report)
- clearskysec.com — Fox Kitten (report)
- clearskysec.com — Pay2Kitten (report)
External references
- mitre-attack — G0117
- UNC757
- Pioneer Kitten
- Parisite
- RUBIDIUM
- Lemon Sandstorm
- CISA AA20-259A Iran-Based Actor September 2020
- ClearSky Pay2Kitten December 2020
- ClearkSky Fox Kitten February 2020
- Dragos PARISITE
- Microsoft Threat Actor Naming July 2023
- CrowdStrike PIONEER KITTEN August 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy