Domestic Kitten

Aliases: Bouncing Golf, APT-C-50

First seen
2016-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:55:39

Targeted industries: government-and-public-sector

Targeted regions: country_code:ir

Context

An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along with surrounding voice recordings. Researchers with CheckPoint discovered the attack and named it Domestic Kitten. The targets are Kurdish and Turkish natives, and ISIS supporters, all Iranian citizens.

Reports & references

  • bleepingcomputer.com — Domestic Kitten Apt Operates In Silence Since 2016 (report)
  • Trend Micro — Mobile Cyberespionage Campaign Bouncing Golf Affects Middle East (report)
  • ESET — Domestic Kitten Campaign Spying Iranian Citizens Furball Malware (report)
  • research.checkpoint.com — Domestic Kitten An Inside Look At The Iranian Surveillance Operations (report)

External references