← All actors Recent activity

Bouncing Golf G0097

DOMESTICKITTEN · apt-c-50

Indicators
42
Source reports
21
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20182026

Overview 42 indicators

Bouncing Golf is a cyberespionage campaign targeting Middle Eastern countries.

domain23G0097-domain.txt
url_path13G0097.json
url5G0097.json
ipv41G0097.json

Techniques 1 ATT&CK

Open in ATT&CK Navigator → or download the layer (1 techniques, layer 4.5)

Software 1

Principal sources 21 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 42 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. or earlier 3 domainthis year

    x.com/ThreatBookLabs/status/20032619204390913…

    androidsecurityupdate.com
    androidsystemsupdate.com
    googleupdateservicese.com

  2. 3 domain2 yrs ago

    twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…

    arzdigitals.com
    ns1.googleassisstants.com
    ns2.googleassisstants.com

  3. 3 url_path4 yrs ago

    x.com/ThreatBookLabs/status/20032619204390913…

    /farahv2.apk
    /negahdarigiahanv2.apk
    /ostadshajarianv5.apk

  4. 3 url_path4 yrs ago

    twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…

    /mmh/gt-func.php
    /mmh/lg-upld.php
    /mmh/on-answ.php

  5. 3 url_path4 yrs ago

    twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…

    /msd/gt-func.php
    /msd/lg-upld.php
    /msd/on-answ.php

  6. 1 url_path4 yrs ago

    x.com/ThreatBookLabs/status/20032619204390913…

    /sarayemaghale.apk

  7. 1 domain4 yrs ago

    welivesecurity.com/2022/10/20/domestic-kitten-campaign-spy…

    sarayemaghale.hami24.net

  8. 2 domain4 yrs ago

    github.com/ti-research-io/ti/blob/main/ioc_extende…

    googlextabv.com
    newportschoolupdateserver.com

  9. 1 domain4 yrs ago

    virustotal.com/gui/file/a7edd5586ac6cd64eaa1d3fd19077b…

    padre914.com

  10. 3 domain5 yrs ago

    twitter.com/felixaime/status/1353622368913133569 · twitter.com/malwrhunterteam/status/1753545424508440… · virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed… · virustotal.com/gui/ip-address/62.112.8.199/relations · virustotal.com/gui/ip-address/62.112.8.244/relations · virustotal.com/gui/ip-address/62.112.8.60/relations · virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bb… · virustotal.com/gui/file/fcd0be3ff03bd5bfe725c63e274218… · virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f… · virustotal.com/gui/file/679355b0f689d745eb6943ed3aa821…

    androidsystemswebview.com
    googleassisstants.com
    googleservicesforar.com

  11. 3 url_path6 yrs ago

    research.checkpoint.com/domestic-kitten-an-iranian-surveillance… · twitter.com/malwrhunterteam/status/1340344596698677… · virustotal.com/gui/file/bd7779e6100e07b3eae67bfcdc53f1…

    /hass/answer.php
    /hass/get-function.php
    /hass/upload-log.php

  12. 3 domain6 yrs ago

    blackberry.com/content/dam/blackberry-com/asset/enterp…

    systemdriverupdate.com
    ydownyload.net
    ynewnow.net

  13. 3 domain, 1 ipv4, 1 url7 yrs ago

    twitter.com/blackorbird/status/1181868468620017665 … · mp.weixin.qq.com/s/yaLC8gs-U92X6WnYzuuQ7w · otx.alienvault.com/pulse/5d9db01cc5328d4649e0594c

    domainappsoftupdate.com
    domainlohefeshordeh.net
    domainychatonline.net
    ipv4198.50.220.44:80
    urlhttp://46.4.143.130

  14. 4 domain, 4 url8 yrs ago

    research.checkpoint.com/domestic-kitten-an-iranian-surveillance… · twitter.com/malwrhunterteam/status/1340344596698677… · virustotal.com/gui/file/bd7779e6100e07b3eae67bfcdc53f1…

    domainfirmwaresystemupdate.com
    domaingeorgethompson.space
    domainronaldlubbers.site
    domainstevenwentz.com
    urlhttp://162.248.247.172
    urlhttp://190.2.144.140
    urlhttp://190.2.145.145
    urlhttp://89.38.98.49

Further reading 23