Rampant Kitten is an Iran-focused threat actor name used in public reporting for activity targeting dissidents and minority communities in Iran. The group has been associated with Android malware designed to intercept and steal SMS-based two-factor authentication codes, including messages used by Google authentication workflows, and to forward text messages to the operators. This indicates an emphasis on compromising mobile devices to facilitate account access and information theft rather than disruptive or destructive operations. Known aliases include RampantKitten and rampant_kitten. Publicly available information in this context supports mobile malware-enabled collection of authentication material and message data, but does not provide high-confidence evidence for broader operational scope, formal state attribution, or additional sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RampantKitten is a threat group named by vendors such as Checkpoint, Kaspersky, and ClearSky, not CrowdStrike. No specific activity is described in this content.
Conducting a surveillance campaign targeting dissidents and minorities in Iran using Android malware hidden in a lure app to intercept SMS-based 2FA codes, harvest contacts and messages, record audio, and support credential-phishing-based account compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.