Overview 36 indicators
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.
| domain | 32 | G0137-domain.txt |
| url_path | 4 | G0137.json |
Techniques 6 ATT&CK
Open in ATT&CK Navigator → or download the layer (6 techniques, layer 4.5)
- T1036.002 Right-to-Left Override
- T1036.005 Match Legitimate Resource Name or Location
- T1204.002 Malicious File
- T1566.001 Spearphishing Attachment
- T1583.001 Domains
- T1588.002 Tool
Software 2
Principal sources 18 reports
Ranked by how many of this actor's indicators each report brought in.
- 21x.com/malwrhunterteam/status/2016245674635923…
- 21x.com/malwrhunterteam/status/2016252181825946…
- 21x.com/skocherhan/status/2016456574731010546
- 21virustotal.com/gui/file/400eb6a94810323a1fc5f8ab31c682…
- 21virustotal.com/gui/file/66dcd98c6b310f4429890821e609d4…
- 21virustotal.com/gui/file/51a6686b8c5ec7c610637398f3de43…
- 13twitter.com/360CoreSec/status/1407604585896632323
- 13twitter.com/360CoreSec/status/1407653661816201226
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 36 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/malwrhunterteam/status/2016245674635923… · x.com/malwrhunterteam/status/2016252181825946… · x.com/skocherhan/status/2016456574731010546 · virustotal.com/gui/file/400eb6a94810323a1fc5f8ab31c682… · virustotal.com/gui/file/66dcd98c6b310f4429890821e609d4… · virustotal.com/gui/file/51a6686b8c5ec7c610637398f3de43…
accountes.google.comesignt.website accounts.google.comisignin.online com-accounts.website com-signin.site come-signin.quest comesignt.website comi-site.website comisignin.online google.comisignin.online microsoft.come-site.website microsoft.comi-site.website min.come-site.website min.comi-site.website ns1.com-accounts.website ns1.com-signin.site ns2.com-accounts.website ns2.com-signin.site -
twitter.com/360CoreSec/status/1407604585896632323 · twitter.com/360CoreSec/status/1407653661816201226 · securelist.com/ferocious-kitten-6-years-of-covert-surv… · virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8… · virustotal.com/gui/file/dd54da85e23ca2117ad962934cf1ce… · virustotal.com/gui/file/be984ef82521f1618edda34fd9d173… · virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fc… · virustotal.com/gui/file/e53e265edcec04cdfb0db351397969… · virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e… · virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9…
comuk.space microsoft.comuk.space -
twitter.com/360CoreSec/status/1435077875703562242 · virustotal.com/gui/file/b0d85647a0715e84a569fc79f6df3b…
microcaft.xyz microsoft.microcaft.xyz -
twitter.com/360CoreSec/status/1407604585896632323 · twitter.com/360CoreSec/status/1407653661816201226 · securelist.com/ferocious-kitten-6-years-of-covert-surv… · virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8… · virustotal.com/gui/file/dd54da85e23ca2117ad962934cf1ce… · virustotal.com/gui/file/be984ef82521f1618edda34fd9d173… · virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fc… · virustotal.com/gui/file/e53e265edcec04cdfb0db351397969… · virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e… · virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9…
microsoft.com-view.space microsoft.unupdate.ml microsoft.unupload.xyz microsoft.updatei.com unupdate.ml unupload.xyz -
twitter.com/360CoreSec/status/1407604585896632323 · twitter.com/360CoreSec/status/1407653661816201226 · securelist.com/ferocious-kitten-6-years-of-covert-surv… · virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8… · virustotal.com/gui/file/dd54da85e23ca2117ad962934cf1ce… · virustotal.com/gui/file/be984ef82521f1618edda34fd9d173… · virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fc… · virustotal.com/gui/file/e53e265edcec04cdfb0db351397969… · virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e… · virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9…
aparat.com-view.space com-view.org com-view.space khabarfarsi.com-view.org updatei.com -
x.com/malwrhunterteam/status/2016245674635923… · x.com/malwrhunterteam/status/2016252181825946… · x.com/skocherhan/status/2016456574731010546 · virustotal.com/gui/file/400eb6a94810323a1fc5f8ab31c682… · virustotal.com/gui/file/66dcd98c6b310f4429890821e609d4… · virustotal.com/gui/file/51a6686b8c5ec7c610637398f3de43…
/ech/client.php?u= /ech/echo.php?req=rr&u= /ech/rite.php /up/uploadx.php?=u=
Further reading 19
- attack.mitre.org/groups/G0137
- securelist.com/ferocious-kitten-6-years-of-covert-surv…
- twitter.com/360CoreSec/status/1407653661816201226
- virustotal.com/gui/file/400eb6a94810323a1fc5f8ab31c682…
- x.com/skocherhan/status/2016456574731010546
- virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fc…
- virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e…
- virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9…
- twitter.com/360CoreSec/status/1407604585896632323
- x.com/malwrhunterteam/status/2016245674635923…
- virustotal.com/gui/file/be984ef82521f1618edda34fd9d173…
- virustotal.com/gui/file/b0d85647a0715e84a569fc79f6df3b…
- virustotal.com/gui/file/51a6686b8c5ec7c610637398f3de43…
- virustotal.com/gui/file/dd54da85e23ca2117ad962934cf1ce…
- virustotal.com/gui/file/e53e265edcec04cdfb0db351397969…
- virustotal.com/gui/file/66dcd98c6b310f4429890821e609d4…
- twitter.com/360CoreSec/status/1435077875703562242
- x.com/malwrhunterteam/status/2016252181825946…
- virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8…