RedKittenRedKitten

Also known as: RedKitten

Known aliases
1

Profile

RedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The malware utilizes GitHub and Google Drive for configuration and payload retrieval, while employing Telegram for command and control. Although precise attribution is challenging, the activity exhibits TTPs associated with Iranian state-sponsored actors and linguistic indicators suggest a Farsi-speaking threat actor. RedKitten is characterized as an AI-accelerated campaign exploiting the humanitarian crisis surrounding Iran’s Dey 1404 protests.

Aliases· 1

RedKitten

References

  1. https://harfanglab.io/insidethelab/redkitten-ai-accelerated-campaign-targeting-iranian-protests/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Ferocious Kitten
Actor
Flash Kitten
Actor
Fox Kitten
Actor
BANISHED KITTEN
Actor
CopyKittens
Actor
TRACER KITTEN
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.