ATT&CKGroupsFox Kitten

Fox Kitten

G0117

Threat group.View on attack.mitre.org

About this group

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.

Techniques used41

Procedure examples41

TechniqueProcedure example
T1003.001
LSASS Memory

Fox Kitten has used prodump to dump credentials from LSASS.

T1003.003
NTDS

Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.

T1005
Data from Local System

Fox Kitten has searched local system resources to access sensitive documents.

T1012
Query Registry

Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat.

T1018
Remote System Discovery

Fox Kitten has used Angry IP Scanner to detect remote systems.

T1021.001
Remote Desktop Protocol

Fox Kitten has used RDP to log in and move laterally in the target environment.

T1021.002
SMB/Windows Admin Shares

Fox Kitten has used valid accounts to access SMB shares.

T1021.004
SSH

Fox Kitten has used the PuTTY and Plink tools for lateral movement.

T1021.005
VNC

Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement.

T1027.010
Command Obfuscation

Fox Kitten has base64 encoded scripts to avoid detection.

T1027.013
Encrypted/Encoded File

Fox Kitten has base64 encoded payloads to avoid detection.

T1036.004
Masquerade Task or Service

Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location

Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate.

T1039
Data from Network Shared Drive

Fox Kitten has searched network shares to access sensitive documents.

T1046
Network Service Discovery

Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports.

View all 41 procedure examples

Software5

Campaigns0

None recorded.

References4

  1. ClearSky Pay2Kitten December 2020 Open source
    ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.
  2. ClearkSky Fox Kitten February 2020 Open source
    ClearSky. (2020, February 16). Fox Kitten – Widespread Iranian Espionage-Offensive Campaign. Retrieved December 21, 2020.
  3. CrowdStrike PIONEER KITTEN August 2020 Open source
    Orleans, A. (2020, August 31). Who Is PIONEER KITTEN?. Retrieved December 21, 2020.
  4. Dragos PARISITE Open source
    Dragos. (n.d.). PARISITE. Retrieved December 21, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.