Check Point Research reported that the Rampant Kitten espionage campaign targeted Iranian expats, dissidents, minorities, and anti-regime organizations in a long-running intelligence-gathering operation attributed to Iran-linked actors. The activity focused on collecting sensitive victim data, including Telegram Desktop files, KeePass password data, documents, and SMS-based two-factor authentication codes, indicating a strong emphasis on surveillance of perceived opponents of the Iranian regime.
Researchers tied the operation to multiple malware families and infrastructure clusters active since 2014, including TelB, TelAndExt, a Python infostealer, and HookInjEx. The attackers used several delivery methods across platforms, including malicious documents, fake software downloads, phishing pages impersonating Telegram, Windows infostealers, and an Android backdoor, showing a sustained and multi-vector effort to compromise targets and exfiltrate communications and credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers observed the TelB variant active from June 2020 to July 2020. This Delphi 64-bit infostealer focused on Telegram Desktop theft and used SOAP-based communications with attacker-controlled domains.
The TelAndExt variant began operating in May 2019 as a Delphi 32-bit Telegram-focused infostealer. It used FTP for command-and-control or exfiltration and was linked to the same campaign infrastructure.
A Python-based infostealer tied to the campaign was active from February 2018 to January 2020. It targeted data from Telegram, Chrome, Firefox, Edge, and Paltalk NG.
Researchers identified the HookInjEx variant as part of the same actor cluster, with activity beginning in December 2014. This malware stole browser data, audio, keystrokes, clipboard contents, and later Telegram Desktop data, using FTP for exfiltration.
Check Point Research published findings on a long-running surveillance operation attributed to Iranian-linked actors targeting Iranian expats, dissidents, minorities, and anti-regime organizations. The report linked multiple malware families, Android spyware, and Telegram phishing infrastructure used for intelligence collection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.