G0117

G0117Fox Kitten

Description

[Fox Kitten](https://attack.mitre.org/groups/G0117) is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. [Fox Kitten](https://attack.mitre.org/groups/G0117) has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)(Citation: Dragos PARISITE )(Citation: ClearSky Pay2Kitten December 2020)

References

  1. https://attack.mitre.org/groups/G0117
  2. https://us-cert.cisa.gov/ncas/alerts/aa20-259a
  3. https://www.clearskysec.com/wp-content/uploads/2020/12/Pay2Kitten.pdf
  4. https://www.clearskysec.com/fox-kitten/
  5. https://www.dragos.com/threat/parisite/
  6. https://www.crowdstrike.com/blog/who-is-pioneer-kitten/

Software attributed to this1

TypeTargetConfidenceTier
SoftwarePay2Keys0556100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
Ferocious Kitten
Group
Charming Kitten
Actor
Flash Kitten
Actor
TRACER KITTEN
Actor
CopyKittens
Actor
Flying Kitten
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.