Nemesis Kitten is an Iranian threat actor associated with the broader APT35/Phosphorus ecosystem and widely tracked under aliases including Cobalt Mirage, DEV-0270, Storm-0270, TunnelVision, and UNC2448. The actor has been linked to contractor-supported operations involving Afkar System and Najee Technologies, entities assessed to support Iranian state cyber activity and associated with the Islamic Revolutionary Guard Corps intelligence apparatus. Reporting also describes sub-clustering within the activity, including a Cluster B element tied to the Drokbk malware family. The group conducts mixed operations spanning espionage, financially motivated ransomware, and disruptive activity. It has targeted organizations in the United States, Israel, Europe, and Australia, and has been associated with intrusions against U.S. companies, U.S. government-related victims, and Israeli targets. Victim sectors and themes include government and public sector entities, media organizations, critical infrastructure, and broader enterprise environments reached through opportunistic exploitation. Nemesis Kitten is notable for opportunistic scan-and-exploit operations against internet-facing systems, including exploitation of Fortinet FortiOS, Microsoft Exchange ProxyShell, VMware Horizon Log4Shell-related flaws, and other widely exploited vulnerabilities. Post-compromise tradecraft includes deployment of web shells, use of Fast Reverse Proxy tooling and customized variants such as TunnelFish, PowerShell-based payload delivery, credential harvesting, creation of privileged accounts, lateral movement over remote administration protocols, and persistence through services or other access mechanisms. The actor has also used living-off-the-land encryption via BitLocker and has deployed DiskCryptor in ransomware operations. Ransomware activity attributed to this actor includes encryption of victim systems and, in some cases, theft of data prior to encryption with subsequent leaking or extortion pressure. Reporting characterizes some operations as ransomware disguised as hacktivism and notes overlap between financially motivated attacks and intelligence collection, complicating motive assessment in individual incidents. Malware and tooling associated with the actor include Drokbk, used post-intrusion for persistence and command execution, as well as FRP-based remote access tooling, PowerShell scripts, Ngrok, and other administrative utilities. Drokbk-linked activity has used dead-drop resolver techniques through legitimate platforms to dynamically locate command-and-control infrastructure, reflecting an emphasis on blending malicious traffic with normal cloud service usage. Nemesis Kitten should be understood as part of the Iranian state-linked intrusion landscape in which contractor-operated teams support both strategic collection and revenue-generating operations. Its operational profile combines broad vulnerability exploitation, practical post-exploitation tradecraft, and ransomware deployment, making it one of the more hybrid Iranian threat clusters bridging espionage and cybercrime-style monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
In this incident, COBALT MIRAGE exploited the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207). | In this incident, COBALT MIRAGE exploited the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207). Although the ProxyShell vulnerabilities were disclosed in August 2021, COBALT MIRAGE continues to have success exploiting them to compromise organizations.
CISA and the FBI issued a joint advisory warning of ongoing exploitation of the Log4Shell vulnerability (CVE-2021-44228) on November 16. The advisory noted that an unspecified Iran-linked threat actor group had exploited the vulnerability during an intrusion into a Federal Civilian Executive Branch (FCEB) organization’s network earlier this year.
In this incident, COBALT MIRAGE exploited the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207).
In this incident, COBALT MIRAGE exploited the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207).
The February intrusion that Secureworks incident responders investigated began with a compromise of a VMware Horizon server using two Log4j vulnerabilities (CVE-2021-44228 and CVE-2021-45046).
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in attribution discussion as an alternative tracking label for some activity associated by others with Phosphorus.
Suspected IRGC-affiliated ransomware operator using hacktivist branding and psychological operations; employs data theft + encryption + leak (double extortion) to undermine confidence in critical infrastructure.
Referenced as an established Iranian APT with TTP overlap to RedKitten; mentioned in references in connection with the Drokbk backdoor (not described in-body).
Iranian nation-state group referenced for prior use of GitHub as a delivery conduit for a backdoor (Drokbk), providing precedent for the GitHub dead-drop technique.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.