Fox Kitten

APT / StateG0117 ↗
Origin🇮🇷 Irã
Techniques (MITRE ATT&CK)41
SourceMITRE ATT&CK
0
Also known as:Lemon SandstormPARISITEPIONEER KITTENParisitePioneer KittenRUBIDIUMUNC757

About the group

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity59
Impact: High
T1190T1053.005T1136.001T1546.008T1012T1021.001ENTRYInitial accessExploitPublic-Facing App…EXECExecutionScheduled TaskPERSPersistenceLocal AccountPRIVPrivilege escalationAccessibilityFeaturesDISCDiscoveryQuery RegistryLATLateral movementRemote DesktopProtocolCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 4

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 8

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.76.165.219:443SystemBCthreatfox
ip:port45.86.230.112:4001SystemBCthreatfox
domainpaladin5.comSystemBCthreatfox
domainanzo11rikasha22b.pwSystemBCthreatfox
domainkall4234ribk3assa.pwSystemBCthreatfox
ip:port94.232.46.202:4321SystemBCthreatfox
sha256_hash1eb027a9844495e9a3c64bc0c7ea645058933a9b18cc98ff3f42a7b1a9142753SystemBCmalwarebazaar
ip:port34.171.171.32:4001SystemBCthreatfox

Fox Kitten uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →