Domestic Kitten
Aliases: Bouncing Golf, APT-C-50
- First seen
- 2016-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:55:39
Targeted industries: government-and-public-sector
Targeted regions: country_code:ir
Context
An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along with surrounding voice recordings. Researchers with CheckPoint discovered the attack and named it Domestic Kitten. The targets are Kurdish and Turkish natives, and ISIS supporters, all Iranian citizens.
Reports & references
- bleepingcomputer.com — Domestic Kitten Apt Operates In Silence Since 2016 (report)
- Trend Micro — Mobile Cyberespionage Campaign Bouncing Golf Affects Middle East (report)
- ESET — Domestic Kitten Campaign Spying Iranian Citizens Furball Malware (report)
- research.checkpoint.com — Domestic Kitten An Inside Look At The Iranian Surveillance Operations (report)