LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0117: Fox Kitten

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.[1][2][3][4]

EnterpriseG0117GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0117: Fox Kitten describes [Fox Kitten](https://attack.mitre.org/groups/G0117) is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. [Fox Kitten](https://attack.mitre.org/groups/G0117) has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KI...

Executive priority

G0117: Fox Kitten is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0117: Fox Kitten by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0117: Fox Kitten appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Fox Kitten

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

41 rows
DomainIDNameRelationship / procedure
EnterpriseT1105Ingress Tool Transfer

Fox Kitten has downloaded additional tools including PsExec directly to endpoints.[5]

EnterpriseT1059Command and Scripting Interpreter

Fox Kitten has used a Perl reverse shell to communicate with C2.[4]

EnterpriseT1530Data from Cloud Storage

Fox Kitten has obtained files from the victim's cloud storage instances.[5]

EnterpriseT1018Remote System Discovery

Fox Kitten has used Angry IP Scanner to detect remote systems.[5]

EnterpriseT1110Brute Force

Fox Kitten has brute forced RDP credentials.[4]

EnterpriseT1136.001Local AccountSub-technique

Fox Kitten has created a local user account with administrator privileges.[4]

EnterpriseT1560.001Archive via UtilitySub-technique

Fox Kitten has used 7-Zip to archive data.[5]

EnterpriseT1027.010Command ObfuscationSub-technique

Fox Kitten has base64 encoded scripts to avoid detection.[5]

EnterpriseT1005Data from Local System

Fox Kitten has searched local system resources to access sensitive documents.[5]

EnterpriseT1585Establish Accounts

Fox Kitten has created KeyBase accounts to communicate with ransomware victims.[4]CitationCheck Point Pay2Key November 2020

EnterpriseT1021.005VNCSub-technique

Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement.[5]

EnterpriseT1552.001Credentials In FilesSub-technique

Fox Kitten has accessed files to gain valid credentials.[5]

EnterpriseT1217Browser Information Discovery

Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets.[5]

EnterpriseT1059.003Windows Command ShellSub-technique

Fox Kitten has used cmd.exe likely as a password changing mechanism.[5]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Fox Kitten has base64 encoded payloads to avoid detection.[5]

EnterpriseT1213.005Messaging ApplicationsSub-technique

Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information.[5]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Fox Kitten has used valid accounts to access SMB shares.[5]

EnterpriseT1190Exploit Public-Facing Application

Fox Kitten has exploited known vulnerabilities in Fortinet, PulseSecure, and Palo Alto VPN appliances.[1][3][2][5][4]

EnterpriseT1555.005Password ManagersSub-technique

Fox Kitten has used scripts to access credential information from the KeePass database.[5]

EnterpriseT1003.003NTDSSub-technique

Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.[5]

EnterpriseT1087.001Local AccountSub-technique

Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts.[5]

EnterpriseT1087.002Domain AccountSub-technique

Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts.[5]

EnterpriseT1021.004SSHSub-technique

Fox Kitten has used the PuTTY and Plink tools for lateral movement.[5]

EnterpriseT1505.003Web ShellSub-technique

Fox Kitten has installed web shells on compromised hosts to maintain access.[5][4]

EnterpriseT1053.005Scheduled TaskSub-technique

Fox Kitten has used Scheduled Tasks for persistence and to load and execute a reverse proxy binary.[5][4]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate.[5]

EnterpriseT1003.001LSASS MemorySub-technique

Fox Kitten has used prodump to dump credentials from LSASS.[5]

EnterpriseT1090Proxy

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.[5][4]CitationCheck Point Pay2Key November 2020

EnterpriseT1012Query Registry

Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat.[5]

EnterpriseT1572Protocol Tunneling

Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion.[2][5][4]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Fox Kitten has used RDP to log in and move laterally in the target environment.[5][4]

EnterpriseT1102Web Service

Fox Kitten has used Amazon Web Services to host C2.[4]

EnterpriseT1039Data from Network Shared Drive

Fox Kitten has searched network shares to access sensitive documents.[5]

EnterpriseT1078Valid Accounts

Fox Kitten has used valid credentials with various services during lateral movement.[5]

EnterpriseT1046Network Service Discovery

Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports.[5][4]

EnterpriseT1546.008Accessibility FeaturesSub-technique

Fox Kitten has used sticky keys to launch a command prompt.[5]

EnterpriseT1585.001Social Media AccountsSub-technique

Fox Kitten has used a Twitter account to communicate with ransomware victims.[4]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate.[5]

EnterpriseT1059.001PowerShellSub-technique

Fox Kitten has used PowerShell scripts to access credential data.[5]

EnterpriseT1083File and Directory Discovery

Fox Kitten has used WizTree to obtain network files and directory listings.[5]

EnterpriseT1210Exploitation of Remote Services

Fox Kitten has exploited known vulnerabilities in remote services including RDP.[1][2][4]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0556: Pay2Key

Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli companies. Pay2Key has been incorporated with a leak site to display stolen sensitive information to further pressure victims into payment.[1][2]

Windows
ToolEnterprise

S0508: ngrok

ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.[1][2][3][4]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S9001: SystemBC

SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.[1][2][3][4][5]

LinuxWindows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
2.0
Created
Modified
Raw hash
db83c009797f0f23...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.22.0Current bundledb83c009797f…
19.12.0Older bundle99cde31d2ff5…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ClearkSky Fox Kitten February 2020

    ClearSky. (2020, February 16). Fox Kitten – Widespread Iranian Espionage-Offensive Campaign. Retrieved December 21, 2020.

    Open source URL
  2. [2]
    CrowdStrike PIONEER KITTEN August 2020

    Orleans, A. (2020, August 31). Who Is PIONEER KITTEN?. Retrieved December 21, 2020.

    Open source URL
  3. [3]
    Dragos PARISITE

    Dragos. (n.d.). PARISITE. Retrieved December 21, 2020.

    Open source URL
  4. [4]
    ClearSky Pay2Kitten December 2020

    ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.

    Open source URL
  5. [5]
    CISA AA20-259A Iran-Based Actor September 2020

    CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020.

    Open source URL
  6. [6]
    Lemon Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  7. [7]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  8. [8]
    Parisite

    (Citation: Dragos PARISITE )(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)

  9. [9]
    Pioneer Kitten

    (Citation: CrowdStrike PIONEER KITTEN August 2020)(Citation: CISA AA20-259A Iran-Based Actor September 2020)

  10. [10]
    RUBIDIUM

    (Citation: Microsoft Threat Actor Naming July 2023)

  11. [11]
    UNC757

    (Citation: CISA AA20-259A Iran-Based Actor September 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)

  12. [12]
    mitre-attackG0117
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.