Fox Kitten, also tracked as Lemon Sandstorm, Pioneer Kitten, UNC757, and Parisite, is an Iranian state-sponsored threat actor linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2017, the group is associated with both cyberespionage and ransomware-related operations and is known for targeting critical infrastructure and other strategically significant organizations, particularly in the Middle East. The actor has conducted long-duration intrusions characterized by stolen-credential access, deployment of web shells and custom backdoors, long-term persistence, and repeated efforts to regain access after eviction. In one prominent campaign against a Middle Eastern critical national infrastructure provider, the group maintained access for nearly two years and focused heavily on reaching operational technology-related environments. Investigators assessed the operation was oriented toward sustained access and strategic positioning rather than large-scale data theft, with the apparent objective of enabling future intelligence collection or disruptive action in the event of regional conflict. Fox Kitten uses a mix of hands-on-keyboard tradecraft and bespoke malware, including custom backdoors such as HanifNet, HXLibrary, and NeoExpressRAT. Reported behavior includes reconnaissance, credential theft, targeted brute-force activity, spear-phishing, exploitation of known vulnerabilities in internet-facing systems, persistence through multiple backdoors and web shells, and attempts to re-establish footholds after remediation. The group has also been associated with exploitation of VPN and firewall vulnerabilities and collaboration with ransomware operators, including activity affecting healthcare and information technology organizations in the United States. The actor’s operations demonstrate strong operational security, patience, and an emphasis on pre-positioning inside victim networks. In critical infrastructure cases, the group has shown particular interest in segmented environments adjacent to operational technology, suggesting a strategic focus on infrastructure access that could support espionage, disruption, or destructive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pioneer Kitten is an IRGC-linked group known for ransomware attacks and espionage, targeting telecommunications, healthcare, and IT in the US, Israel, and Europe. They exploit VPN/firewall vulnerabilities and collaborate with ransomware groups.
Lemon Sandstorm is an Iran-linked APT group known for targeting critical national infrastructure, government, and financial institutions, primarily in the Middle East. Their operations focus on maintaining long-term access to OT environments, likely for future destructive attacks, and they have a history of information theft, disruption, and selling access to ransomware actors.
Lemon Sandstorm is known for conducting long-term cyberespionage campaigns targeting critical infrastructure, with a focus on operational technology networks. The group is associated with both espionage and ransomware operations, and is persistent in maintaining access to victim environments, using a variety of techniques including webshells, backdoors, phishing, and exploitation of known vulnerabilities.
Lemon Sandstorm is conducting long-term espionage and network prepositioning operations against Middle Eastern critical infrastructure, using custom backdoors to maintain persistent access for strategic advantage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.