Fox Kitten is an Iranian state-linked intrusion set associated with espionage-driven operations and commonly tracked under aliases including Lemon Sandstorm, Pioneer Kitten, Parisite, Rubidium, UNC757, Br0k3r, and Foxkitten. The group has been linked to activity overlapping with or associated by some vendors with MuddyWater-related reporting, though naming and clustering vary across the industry. Fox Kitten is known for targeting organizations in the United States, Israel, the United Arab Emirates, Australia, Azerbaijan, and other countries, with victimology that includes government and public-sector entities, information technology environments, and enterprise networks. Reported operations show a strong emphasis on gaining access to internet-facing systems and then expanding access through post-compromise discovery, credential access, and lateral movement. Observed tradecraft includes exploitation of public-facing applications and remote services for initial access and pivoting, use of PowerShell and other command interpreters for execution, and DNS-based command-and-control techniques. The group has conducted extensive internal reconnaissance, including browsing service-account information through LDAP tooling, enumerating files and directories on local and network-accessible systems, searching local resources for sensitive documents, and using browser artifacts such as Chrome bookmarks to identify internal resources and assets. Fox Kitten has also accessed Windows Registry hives and related user hive files for host discovery and follow-on collection. Credential access is a recurring element of Fox Kitten operations. The group has accessed files to obtain valid credentials and used PowerShell scripts to collect credential data. Reporting also associates the actor with access to credential-bearing application stores and configuration locations. Additional observed behavior includes use of reverse shells, likely password-changing activity through command-line utilities, and masquerading through legitimate-looking names for binaries and configuration artifacts to reduce suspicion. At a behavioral level, Fox Kitten demonstrates capabilities spanning initial access, reconnaissance, credential theft, persistence, privilege escalation, lateral movement, post-exploitation, defense evasion, exfiltration, and spoofing or masquerading. The actor is best characterized as an Iranian espionage operator focused on long-term network access, internal discovery, and collection rather than financially motivated ransomware activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
28 malware families attributed to this actor across reporting.
23 additional families tracked in Mallory.
21 CVEs this actor has used in observed campaigns. 21 of them exploited in the wild.
CISA and the FBI have observed the threat actor exploiting multiple CVEs, including CVE-2019-11510, CVE-2019-11539, CVE-2019-19781, and CVE-2020-5902.
CISA and the FBI have observed the threat actor exploiting multiple CVEs, including CVE-2019-11510, CVE-2019-11539, CVE-2019-19781, and CVE-2020-5902.
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781.
CISA and the FBI have observed the threat actor exploiting multiple CVEs, including CVE-2019-11510, CVE-2019-11539, CVE-2019-19781, and CVE-2020-5902.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
16 more CVEs tied to this actor tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed incidentally in the detection's ATT&CK annotation list.
Mentioned only as an annotated threat actor associated with this generic Linux shared-memory execution detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.