Researchers reported that the Iranian-linked Domestic Kitten surveillance operation, also tracked as APT-C-50, deployed an updated version of its FurBall Android spyware in campaigns targeting Iranian citizens. The malware was delivered through fake websites impersonating legitimate services, including a spoofed English-to-Persian translation site that served a malicious APK named sarayemaghale.apk. Analysis found the newer FurBall variant preserved core spying capabilities while adding obfuscation and refreshed command-and-control infrastructure, helping it evade antivirus detection more effectively than earlier samples.
Domestic Kitten has been tied to a broader long-running surveillance program that used tailored Android apps to monitor specific ethnic, political, and religious groups, including Kurds, Sunni Muslims, ISIS supporters, and other Iranian targets. Earlier research linked the operation to hundreds of victims and showed the spyware could steal screenshots, messages, call logs, ambient audio, contacts, and files from infected devices. In the latest sample, the app requested only contacts and storage permissions—likely to reduce suspicion—while polling its C2 server over HTTP every 10 seconds, underscoring the group’s continued focus on covert mobile surveillance.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers said the earliest malicious Android samples linked to the Domestic Kitten surveillance campaign dated back to 2016. Later reporting also described the FurBall surveillance operation as active since at least 2016.
ESET analyzed a newer FurBall Android spyware sample used in surveillance campaigns targeting Iranian citizens and attributed it to Domestic Kitten/APT-C-50. The sample retained similarities to earlier versions but added obfuscation and updated command-and-control infrastructure while being distributed via fake websites impersonating legitimate services.
Researchers investigating Domestic Kitten said they confirmed the operation's suspected Iranian origin after accessing logs uploaded from infected devices to command-and-control servers. Those logs also showed the campaign had hundreds of victims across targeted groups including Kurds, Sunni Muslims, ISIS supporters, and Iranian citizens.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.