Industrial Serpens, also known as Chrono Kitten, is an Iranian threat actor associated with disruptive cyber operations aligned with Iranian state interests. The group has been linked to attacks intended to cause disruption rather than purely collect intelligence, including ransomware, wiper malware, and hack-and-leak activity. Reporting also associates the actor with the use of Android spyware, password-based intrusion activity, and exploitation of vulnerabilities to gain access and support follow-on operations. Industrial Serpens is part of the broader Iranian state-linked cyber ecosystem that has targeted critical infrastructure and other sensitive sectors during periods of geopolitical tension. Its operational profile fits Iranian campaigns that combine intrusion, disruption, and information effects, and that may be timed to coincide with regional conflict dynamics involving Iran, Israel, and the United States. The actor is therefore best understood as a disruptive Iranian proxy or state-aligned cluster rather than a conventional financially motivated cybercriminal group. Known aliases include Chrono Kitten. High-confidence reporting ties the group to disruptive attacks and intrusion methods including password attacks and vulnerability exploitation, with malware-enabled post-compromise activity involving spyware and destructive tooling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.