Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Persistence (macOS): ~/.local/share/kitty/cat.py + ~/Library/LaunchAgents/com.user.kitty-monitor.plist ; C2 polling via api.github.com/search/commits?q=firedalazer (executes remote Python after RSA-PSS signature verification).
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The monitor polls GitHub commit search for signed instructions and can download and execute follow-on Python payloads.
The monitor polls GitHub commit search for signed instructions and can download and execute follow-on Python payloads.
The payload also installs OS-level background services: a systemd user service on Linux, a LaunchAgent on macOS.
Persistence (macOS): ~/.local/share/kitty/cat.py + ~/Library/LaunchAgents/com.user.kitty-monitor.plist
The monitor polls GitHub commit search for signed instructions and can download and execute follow-on Python payloads.
short-lived OIDC tokens were extracted from the memory of the Runner.Worker process... This attack shares the same TTPs as the 5/19 @antv wave: kitty-monitor, firedalazer, and extraction of Actions secrets from Runner /proc/*/mem .
The payload also installs OS-level background services: a systemd user service on Linux, a LaunchAgent on macOS.
Persistence (macOS): ~/.local/share/kitty/cat.py + ~/Library/LaunchAgents/com.user.kitty-monitor.plist
The May 19 wave also adds kitty-monitor , a persistent GitHub commit-search C2 daemon. It polls GitHub commit search for the keyword firedalazer , validates commands with an embedded RSA public key, downloads the referenced payload, and executes it as Python.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistence and backdoor component used in the Nx Console and related waves, installing cat.py and a LaunchAgent, polling GitHub-based C2, and executing remotely delivered Python after signature verification.
A persistent backdoor component installed as an OS-level background service on Linux and macOS that polls GitHub commit search for signed remote commands.
Persistent GitHub commit-search C2 daemon used by the Shai-Hulud campaign. It survives token rotation by polling GitHub for signed commands, downloading referenced payloads, and executing them.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.