Fox Kitten, also tracked as COBALT FOXGLOVE, Parisite, Pioneer Kitten, UNC757, Lemon Sandstorm, and RUBIDIUM, is an Iranian threat actor active since at least 2017. The group is best known for exploiting vulnerabilities in VPNs and other network appliances to obtain remote access, typically deploying web shells immediately after successful exploitation. It has demonstrated a consistent ability to operationalize newly disclosed remote code execution vulnerabilities very quickly, often automating initial exploitation and triaging compromised environments for follow-on activity. Fox Kitten is widely associated with initial access operations. After compromising edge infrastructure, the group commonly establishes additional access channels, harvests credentials, and reviews files for sensitive information. Reported tooling includes both open-source utilities and custom malware and scripts, reflecting a pragmatic intrusion set focused on speed, scalability, and persistence rather than bespoke implants alone. The actor has targeted organizations in media, aviation, manufacturing, government, information technology, telecommunications, oil and gas, technology, and security-related sectors. The group has primarily targeted organizations in Israel and the United States. It has also been linked to the Pay2Key ransomware ecosystem, although the exact nature of that relationship remains unclear. Overall, Fox Kitten is best characterized as an Iranian intrusion actor specializing in vulnerability exploitation and access enablement, with tradecraft centered on initial compromise of internet-facing infrastructure and subsequent credential and network access expansion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian intrusion activity focused on exploiting VPN/network appliance vulnerabilities for initial access and establishing persistence via web shells.
COBALT FOXGLOVE is an Iranian threat actor focused on espionage, initial access brokering, and credential harvesting. They exploit VPN and network appliance vulnerabilities to gain access, deploy webshells, and hand off compromised targets to other teams or sell access. They target a wide range of industries and are known for rapid adoption of new exploits.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.