Domestic Kitten, also tracked as APT-C-50, is an Iranian state-sponsored intrusion set focused primarily on domestic surveillance and intelligence collection against Iranian citizens. The group has been active since at least 2016 and is notable for sustained mobile surveillance operations using Android spyware, including FurBall. Reporting on Iranian cyber operations places Domestic Kitten among Iran-nexus actors used to monitor individuals inside Iran, aligning the group with state security and regime-stability objectives rather than financially motivated activity. Domestic Kitten’s operations rely heavily on social engineering and deceptive delivery infrastructure. The group has distributed Android spyware through fake websites impersonating legitimate services and has used lures delivered via direct messages, social media posts, email, SMS, and search-engine manipulation. Its mobile malware is designed for covert collection of victim data and has been observed with capabilities that can include theft of contacts, SMS messages, call logs, clipboard contents, device and application information, notification content, and location data, as well as call recording, depending on the permissions requested. More recent FurBall variants have also incorporated stronger obfuscation while retaining command-and-control functionality for ongoing tasking and data theft. Domestic Kitten is best characterized as a surveillance-oriented Iranian threat actor specializing in mobile initial access and persistent collection against civilian targets inside Iran. Known aliases include DomesticKitten, domestic_kitten, and APT-C-50.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Domestic Kitten is an Iran-nexus group focused on domestic surveillance, especially mobile espionage against Iranian citizens, dissidents, journalists, and activists.
Conducting long-running mobile surveillance campaigns against Iranian citizens using the FurBall Android spyware, distributed via fake websites and lures delivered through direct messages, social media posts, emails, SMS, black SEO, and SEO poisoning.
DomesticKitten is a threat group named by vendors such as Checkpoint, Kaspersky, and ClearSky, not CrowdStrike. No specific activity is described in this content.
Observed active in the Middle East (no further details provided).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.