Fox Kitten is an Iranian state-sponsored cyber-espionage threat actor, also tracked as Pioneer Kitten, Lemon Sandstorm, Parisite, Rubidium, br0k3r, and UNC757. The group targets Israeli, U.S., and other Western organizations, including energy-sector entities. Its operations have included exploitation of internet-facing remote-access infrastructure, including Check Point Quantum gateways, to gain initial access. Fox Kitten has established persistence with Windows Scheduled Tasks, including tasks used to load and execute reverse-proxy tooling. It has used PowerShell to access credential data; native Windows command-shell activity, including apparent password-changing actions; PsExec; WizTree for network file and directory enumeration; and searches of local system resources for sensitive documents. These activities are consistent with a long-term intelligence-collection mission and post-compromise access operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
25 CVEs this actor has used in observed campaigns. 25 of them exploited in the wild.
The following is the summary of vulnerabilities we attribute with high probability of being potentially exploited by the group: • CVE-2019-11510 Pulse Secure
We have witnessed attempts to exploit the CITRIX vulnerability in Israel since February 2020... As can be seen, this is a reused web shell from Citrix used to exploit CVE-2019-19781 (Citrix NetScaler).
We have witnessed attempts to exploit... the Big F5 vulnerability since June 2020... This server was used in attempted exploitation of the F5 vulnerability (CVE-2020-5902).
The analysis of the infrastructure of Habana identified a vulnerable Fortinet server that was breached and its credentials were leaked to an underground forum. This server was vulnerable to Fortinet SSL VPN (CVE-2018-13379). We assess that this server was hacked by the threat actor using this exploit.
CVE-2024-24919 affects Check Point Quantum and was independently exploited by China-linked PurpleHaze and Iran-linked Fox Kitten.
20 more CVEs tied to this actor tracked in Mallory.
126 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an annotated actor associated with the detection technique.
Listed in the detection annotation metadata.
Fox Kitten is listed in the detection's annotations for MITRE ATT&CK technique T1059 (Command and Scripting Interpreter).
Listed as an annotated threat actor associated with the Socat detection; no actor-specific activity is described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.