← All actors Recent activity

CopyKittens G0052

COPYKITTENS

Indicators
34
Source reports
1
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02

Overview 34 indicators

CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.

domain34G0052-domain.txt

Techniques 8 ATT&CK

Open in ATT&CK Navigator → or download the layer (8 techniques, layer 4.5)

Software 4

Principal sources 1 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 34 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 34 domain9 yrs ago

    s3-eu-west-1.amazonaws.com/minervaresearchpublic/CopyKittens/CopyK…

    alhadath.mobi
    big-windowss.com
    cacheupdate14.com
    fbstatic-a.space
    fbstatic-a.xyz
    fbstatic-akamaihd.com
    gmailtagmanager.com
    haaretz-news.com
    haaretz.link
    heartax.info
    kernel4windows.in
    micro-windows.in
    mswordupdate15.com
    mswordupdate16.com
    mswordupdate17.com
    mywindows24.in
    patch7-windows.com
    patch8-windows.com
    patchthiswindows.com
    walla.link
    wethearservice.com
    wheatherserviceapi.info
    windowkernel.com
    windows-10patch.in
    windows-drive20.com
    windows-india.in
    windows-kernel.in
    windows-my50.com
    windows24-kernel.in
    windowskernel.in
    windowskernel14.com
    windowslayer.in
    windowssup.in
    windowsupup.com

Further reading 5