Fox Kitten

MITRE ATT&CK: G0117 View on attack.mitre.org

Aliases: UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm, PIONEER KITTEN, PARISITE, Fox Kitten, PioneerKitten

First seen
2017-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:33:11

Targeted industries: energy-and-utilities technology-and-telecommunications government-and-public-sector defense-and-aerospace healthcare-and-pharmaceutical manufacturing

Targeted regions: country_code:ae country_code:sa country_code:au country_code:us country_code:de country_code:fr country_code:gb

Context

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.

Detection coverage

  • 7 YARA rules
  • 940 Sigma rules

Malware & tools used

  • Data from Cloud Storage (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Brute Force (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Local Account (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Data from Local System (attack-pattern)
  • Establish Accounts (attack-pattern)
  • VNC (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Messaging Applications (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Password Managers (attack-pattern)
  • NTDS (attack-pattern)
  • Local Account (attack-pattern)
  • Domain Account (attack-pattern)
  • SSH (attack-pattern)
  • Web Shell (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Masquerade Task or Service (attack-pattern)

Reports & references

  • youtu.be — Pbdu8Egwrc4 (report)
  • dragos.com — Parisite (report)
  • dragos.com — The Ics Threat Landscape (report)
  • dragos.com — Na El Threat Perspective 2019 (report)
  • clearskysec.com — Clearsky Fox Kitten Campaign (report)
  • zdnet.com — Fbi Says An Iranian Hacking Group Is Attacking F5 Networking Devices (report)
  • CrowdStrike — Who Is Pioneer Kitten (report)
  • zdnet.com — Iranian Hackers Are Selling Access To Compromised Companies On An Underground Forum (report)
  • CISA — Aa20 259A (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G0117 (report)
  • clearskysec.com — Fox Kitten (report)
  • clearskysec.com — Pay2Kitten (report)

External references