← All actors Recent activity

Ferocious Kitten G0137

FEROCIOUSKITTEN · MarkiRAT

Indicators
36
Source reports
18
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-02-03
20212026

Overview 36 indicators

Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.

domain32G0137-domain.txt
url_path4G0137.json

Techniques 6 ATT&CK

Open in ATT&CK Navigator → or download the layer (6 techniques, layer 4.5)

Software 2

Principal sources 18 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 36 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 17 domainthis year

    x.com/malwrhunterteam/status/2016245674635923… · x.com/malwrhunterteam/status/2016252181825946… · x.com/skocherhan/status/2016456574731010546 · virustotal.com/gui/file/400eb6a94810323a1fc5f8ab31c682… · virustotal.com/gui/file/66dcd98c6b310f4429890821e609d4… · virustotal.com/gui/file/51a6686b8c5ec7c610637398f3de43…

    accountes.google.comesignt.website
    accounts.google.comisignin.online
    com-accounts.website
    com-signin.site
    come-signin.quest
    comesignt.website
    comi-site.website
    comisignin.online
    google.comisignin.online
    microsoft.come-site.website
    microsoft.comi-site.website
    min.come-site.website
    min.comi-site.website
    ns1.com-accounts.website
    ns1.com-signin.site
    ns2.com-accounts.website
    ns2.com-signin.site

  2. 2 domain4 yrs ago

    twitter.com/360CoreSec/status/1407604585896632323 · twitter.com/360CoreSec/status/1407653661816201226 · securelist.com/ferocious-kitten-6-years-of-covert-surv… · virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8… · virustotal.com/gui/file/dd54da85e23ca2117ad962934cf1ce… · virustotal.com/gui/file/be984ef82521f1618edda34fd9d173… · virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fc… · virustotal.com/gui/file/e53e265edcec04cdfb0db351397969… · virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e… · virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9…

    comuk.space
    microsoft.comuk.space

  3. 2 domain5 yrs ago

    twitter.com/360CoreSec/status/1435077875703562242 · virustotal.com/gui/file/b0d85647a0715e84a569fc79f6df3b…

    microcaft.xyz
    microsoft.microcaft.xyz

  4. 6 domain5 yrs ago

    twitter.com/360CoreSec/status/1407604585896632323 · twitter.com/360CoreSec/status/1407653661816201226 · securelist.com/ferocious-kitten-6-years-of-covert-surv… · virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8… · virustotal.com/gui/file/dd54da85e23ca2117ad962934cf1ce… · virustotal.com/gui/file/be984ef82521f1618edda34fd9d173… · virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fc… · virustotal.com/gui/file/e53e265edcec04cdfb0db351397969… · virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e… · virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9…

    microsoft.com-view.space
    microsoft.unupdate.ml
    microsoft.unupload.xyz
    microsoft.updatei.com
    unupdate.ml
    unupload.xyz

  5. 5 domain5 yrs ago

    twitter.com/360CoreSec/status/1407604585896632323 · twitter.com/360CoreSec/status/1407653661816201226 · securelist.com/ferocious-kitten-6-years-of-covert-surv… · virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8… · virustotal.com/gui/file/dd54da85e23ca2117ad962934cf1ce… · virustotal.com/gui/file/be984ef82521f1618edda34fd9d173… · virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fc… · virustotal.com/gui/file/e53e265edcec04cdfb0db351397969… · virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e… · virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9…

    aparat.com-view.space
    com-view.org
    com-view.space
    khabarfarsi.com-view.org
    updatei.com

  6. 4 url_path5 yrs ago

    x.com/malwrhunterteam/status/2016245674635923… · x.com/malwrhunterteam/status/2016252181825946… · x.com/skocherhan/status/2016456574731010546 · virustotal.com/gui/file/400eb6a94810323a1fc5f8ab31c682… · virustotal.com/gui/file/66dcd98c6b310f4429890821e609d4… · virustotal.com/gui/file/51a6686b8c5ec7c610637398f3de43…

    /ech/client.php?u=
    /ech/echo.php?req=rr&u=
    /ech/rite.php
    /up/uploadx.php?=u=

Further reading 19