Threat group.View on attack.mitre.org
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
CopyKittens has used PowerShell Empire. |
| T1090 Proxy |
CopyKittens has used the AirVPN service for operational activity. |
| T1218.011 Rundll32 |
CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode. |
| T1553.002 Code Signing |
CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared. |
| T1560.001 Archive via Utility |
CopyKittens uses ZPP, a .NET console program, to compress files with ZIP. |
| T1560.003 Archive via Custom Method |
CopyKittens encrypts data with a substitute cipher prior to exfiltration. |
| T1564.003 Hidden Window |
CopyKittens has used |
| T1588.002 Tool |
CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.