Fox Kitten is an Iranian state-backed intrusion set associated with long-running espionage, strategic network access, and disruptive operations, particularly against critical infrastructure and organizations of geopolitical interest. The group is also tracked as Lemon Sandstorm, Pioneer Kitten, Parisite, Rubidium, UNC757, and Br0k3r. Reporting has linked it to Iranian government interests and to operations spanning at least the late 2010s through the mid-2020s. Fox Kitten is best known for exploiting vulnerabilities in internet-facing remote access and edge infrastructure, especially VPN and application delivery products, to obtain initial access. The group has been observed leveraging known vulnerabilities in products from Pulse Secure, Fortinet, Palo Alto Networks, Citrix, F5, and other externally exposed enterprise systems, as well as using stolen VPN credentials and password-spraying activity. After access, it commonly establishes persistence through web shells, scheduled tasks, password filter DLLs, remote access software, and proxy tooling. The actor’s post-compromise tradecraft is mature and operationally flexible. Observed behaviors include extensive PowerShell use, credential theft from files and memory, LSASS dumping, harvesting of local account hashes, Active Directory reconnaissance, network scanning, file and directory discovery, collection of sensitive documents, and lateral movement via RDP, SMB, PsExec, SSH, and PowerShell remoting. Fox Kitten frequently uses tunneling and reverse-proxy tools to move through segmented environments and maintain covert operator access. It also employs defense-evasion measures such as masquerading binaries and configuration artifacts as legitimate Windows components and using scheduled task names and paths that blend into normal administration. Victimology consistently centers on government, utilities, energy, oil and gas, aerospace, manufacturing, and other industrial or strategic sectors across the Middle East, North America, and Europe. The group has been tied to intrusions into electric and oil-and-gas entities and to prolonged access operations against Middle Eastern critical infrastructure, including environments adjacent to operational technology. Its activity is widely assessed as focused primarily on espionage and strategic prepositioning, though some campaigns have had disruptive characteristics. Fox Kitten has also been linked to the Pay2Key operation targeting Israeli organizations in 2020. That campaign combined network intrusion, data theft, encryption, and public leaking of stolen information, and has been assessed by multiple researchers as aligned more closely with Iranian strategic disruption of Israeli interests than with purely profit-driven ransomware. In that context, Fox Kitten demonstrated ransomware-style extortion tactics including encryption and leak-site pressure, but its dominant profile remains that of a state-backed access and espionage actor rather than a conventional cybercriminal ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
25 CVEs this actor has used in observed campaigns. 25 of them exploited in the wild.
The following is the summary of vulnerabilities we attribute with high probability of being potentially exploited by the group: • CVE-2019-11510 Pulse Secure
We have witnessed attempts to exploit the CITRIX vulnerability in Israel since February 2020... As can be seen, this is a reused web shell from Citrix used to exploit CVE-2019-19781 (Citrix NetScaler).
We have witnessed attempts to exploit... the Big F5 vulnerability since June 2020... This server was used in attempted exploitation of the F5 vulnerability (CVE-2020-5902).
The analysis of the infrastructure of Habana identified a vulnerable Fortinet server that was breached and its credentials were leaked to an underground forum. This server was vulnerable to Fortinet SSL VPN (CVE-2018-13379). We assess that this server was hacked by the threat actor using this exploit.
The following is the summary of vulnerabilities we attribute with high probability of being potentially exploited by the group: • CVE-2018-1579 Palo Alto Networks VPN
20 more CVEs tied to this actor tracked in Mallory.
124 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed incidentally in the detection's ATT&CK annotation list.
Mentioned only as an annotated threat actor associated with this generic Linux shared-memory execution detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.