Overview 34 indicators
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.
| domain | 34 | G0052-domain.txt |
Techniques 8 ATT&CK
Open in ATT&CK Navigator → or download the layer (8 techniques, layer 4.5)
- T1059.001 PowerShell
- T1090 Proxy
- T1218.011 Rundll32
- T1553.002 Code Signing
- T1560.001 Archive via Utility
- T1560.003 Archive via Custom Method
- T1564.003 Hidden Window
- T1588.002 Tool
Software 4
Principal sources 1 reports
Ranked by how many of this actor's indicators each report brought in.
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 34 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
s3-eu-west-1.amazonaws.com/minervaresearchpublic/CopyKittens/CopyK…
alhadath.mobi big-windowss.com cacheupdate14.com fbstatic-a.space fbstatic-a.xyz fbstatic-akamaihd.com gmailtagmanager.com haaretz-news.com haaretz.link heartax.info kernel4windows.in micro-windows.in mswordupdate15.com mswordupdate16.com mswordupdate17.com mywindows24.in patch7-windows.com patch8-windows.com patchthiswindows.com walla.link wethearservice.com wheatherserviceapi.info windowkernel.com windows-10patch.in windows-drive20.com windows-india.in windows-kernel.in windows-my50.com windows24-kernel.in windowskernel.in windowskernel14.com windowslayer.in windowssup.in windowsupup.com