RedKitten is an Iran-linked, Farsi-speaking cyber-espionage threat cluster aligned with Iranian state interests and first publicly observed in early 2026 during unrest and protest crackdowns in Iran. The actor has targeted Iranian civil society, including human rights NGOs, activists, journalists, academics, and other individuals documenting abuses, with particular emphasis on protest-related themes and Kurdish community targets. Reporting also links the cluster to broader targeting of government officials and business leaders connected to Iran-focused issues. RedKitten is notable for combining social engineering with modular malware and widespread use of legitimate cloud and communications platforms. Its intrusion chains have used spearphishing lures themed around protester deaths and human rights abuses, typically delivered in Farsi-language archives containing malicious Excel documents with VBA macros. Those macros have been assessed as showing signs of AI-assisted or AI-obfuscated development. Execution leads to AppDomainManager injection and deployment of the SloppyMIO backdoor, a modular implant that uses GitHub as a dead-drop resolver, Google Drive for staged configuration and payload retrieval, and Telegram Bot API for command and control and exfiltration. SloppyMIO supports arbitrary command execution, file collection and exfiltration, additional payload delivery, process execution, and scheduled-task persistence. The actor has also operated credential-harvesting infrastructure impersonating communications and email services to steal account credentials and, in some cases, facilitate surveillance-oriented access requests. Use of commoditized platforms such as GitHub, Google Drive, and Telegram complicates infrastructure-based tracking while reflecting an effort to blend malicious traffic with normal services. RedKitten’s tradecraft overlaps with known Iranian intrusion sets including Charming Kitten, Nemesis Kitten, Tortoiseshell, and MuddyWater-linked activity discussed in relation to Operation Olalampo, but available information supports treating RedKitten as a distinct tracked cluster rather than conclusively equating it with those groups. The dominant assessed purpose of the activity is espionage and monitoring of dissidents, activists, and organizations documenting politically sensitive events inside Iran.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actor referenced for AI-accelerated attacks during protests, illustrating operational use of LLM-assisted development and phishing infrastructure.
Named campaign/activity cluster overlapping with MuddyWater TTPs and phishing infrastructure targeting the META region.
State-aligned targeting of Iranian civil society and human rights documentation groups using AI-assisted operations, steganographic configuration retrieval, cloud-hosted payloads, and messaging-platform API C2.
Threat cluster reported targeting NGOs and individuals documenting human rights abuses in Iran, aiming to deploy the custom backdoor SloppyMIO for espionage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.