G0117: Fox Kitten
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.[1][2][3][4]
Security context for executives and security teams
G0117: Fox Kitten describes [Fox Kitten](https://attack.mitre.org/groups/G0117) is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. [Fox Kitten](https://attack.mitre.org/groups/G0117) has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KI...
Executive priority
G0117: Fox Kitten is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0117: Fox Kitten by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0117: Fox Kitten appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Fox Kitten
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1105 | Ingress Tool Transfer | Fox Kitten has downloaded additional tools including PsExec directly to endpoints.[5] |
| Enterprise | T1059 | Command and Scripting Interpreter | Fox Kitten has used a Perl reverse shell to communicate with C2.[4] |
| Enterprise | T1530 | Data from Cloud Storage | Fox Kitten has obtained files from the victim's cloud storage instances.[5] |
| Enterprise | T1018 | Remote System Discovery | Fox Kitten has used Angry IP Scanner to detect remote systems.[5] |
| Enterprise | T1110 | Brute Force | Fox Kitten has brute forced RDP credentials.[4] |
| Enterprise | T1136.001 | Local AccountSub-technique | Fox Kitten has created a local user account with administrator privileges.[4] |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | Fox Kitten has used 7-Zip to archive data.[5] |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | Fox Kitten has base64 encoded scripts to avoid detection.[5] |
| Enterprise | T1005 | Data from Local System | Fox Kitten has searched local system resources to access sensitive documents.[5] |
| Enterprise | T1585 | Establish Accounts | Fox Kitten has created KeyBase accounts to communicate with ransomware victims.[4]CitationCheck Point Pay2Key November 2020 |
| Enterprise | T1021.005 | VNCSub-technique | Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement.[5] |
| Enterprise | T1552.001 | Credentials In FilesSub-technique | Fox Kitten has accessed files to gain valid credentials.[5] |
| Enterprise | T1217 | Browser Information Discovery | Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets.[5] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Fox Kitten has used cmd.exe likely as a password changing mechanism.[5] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Fox Kitten has base64 encoded payloads to avoid detection.[5] |
| Enterprise | T1213.005 | Messaging ApplicationsSub-technique | Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information.[5] |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | Fox Kitten has used valid accounts to access SMB shares.[5] |
| Enterprise | T1190 | Exploit Public-Facing Application | |
| Enterprise | T1555.005 | Password ManagersSub-technique | Fox Kitten has used scripts to access credential information from the KeePass database.[5] |
| Enterprise | T1003.003 | NTDSSub-technique | Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.[5] |
| Enterprise | T1087.001 | Local AccountSub-technique | Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts.[5] |
| Enterprise | T1087.002 | Domain AccountSub-technique | Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts.[5] |
| Enterprise | T1021.004 | SSHSub-technique | Fox Kitten has used the PuTTY and Plink tools for lateral movement.[5] |
| Enterprise | T1505.003 | Web ShellSub-technique | Fox Kitten has installed web shells on compromised hosts to maintain access.[5][4] |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | Fox Kitten has used Scheduled Tasks for persistence and to load and execute a reverse proxy binary.[5][4] |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate.[5] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Fox Kitten has used prodump to dump credentials from LSASS.[5] |
| Enterprise | T1090 | Proxy | Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.[5][4]CitationCheck Point Pay2Key November 2020 |
| Enterprise | T1012 | Query Registry | Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat.[5] |
| Enterprise | T1572 | Protocol Tunneling | Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion.[2][5][4] |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | Fox Kitten has used RDP to log in and move laterally in the target environment.[5][4] |
| Enterprise | T1102 | Web Service | Fox Kitten has used Amazon Web Services to host C2.[4] |
| Enterprise | T1039 | Data from Network Shared Drive | Fox Kitten has searched network shares to access sensitive documents.[5] |
| Enterprise | T1078 | Valid Accounts | Fox Kitten has used valid credentials with various services during lateral movement.[5] |
| Enterprise | T1046 | Network Service Discovery | Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports.[5][4] |
| Enterprise | T1546.008 | Accessibility FeaturesSub-technique | Fox Kitten has used sticky keys to launch a command prompt.[5] |
| Enterprise | T1585.001 | Social Media AccountsSub-technique | Fox Kitten has used a Twitter account to communicate with ransomware victims.[4] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate.[5] |
| Enterprise | T1059.001 | PowerShellSub-technique | Fox Kitten has used PowerShell scripts to access credential data.[5] |
| Enterprise | T1083 | File and Directory Discovery | Fox Kitten has used WizTree to obtain network files and directory listings.[5] |
| Enterprise | T1210 | Exploitation of Remote Services | Fox Kitten has exploited known vulnerabilities in remote services including RDP.[1][2][4] |
Groups, software, and campaigns
S0020: China Chopper
S0556: Pay2Key
Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli companies. Pay2Key has been incorporated with a leak site to display stolen sensitive information to further pressure victims into payment.[1][2]
S0508: ngrok
S0029: PsExec
S9001: SystemBC
SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.[1][2][3][4][5]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.0 | Current bundle | db83c009797f… | ||
| 19.1 | 2.0 | Older bundle | 99cde31d2ff5… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]ClearkSky Fox Kitten February 2020
ClearSky. (2020, February 16). Fox Kitten – Widespread Iranian Espionage-Offensive Campaign. Retrieved December 21, 2020.
Open source URL - [2]CrowdStrike PIONEER KITTEN August 2020
Orleans, A. (2020, August 31). Who Is PIONEER KITTEN?. Retrieved December 21, 2020.
Open source URL - [3]Dragos PARISITE
Dragos. (n.d.). PARISITE. Retrieved December 21, 2020.
Open source URL - [4]ClearSky Pay2Kitten December 2020
ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.
Open source URL - [5]CISA AA20-259A Iran-Based Actor September 2020
CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020.
Open source URL - [6]Lemon Sandstorm
(Citation: Microsoft Threat Actor Naming July 2023)
- [7]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [8]Parisite
(Citation: Dragos PARISITE )(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)
- [9]Pioneer Kitten
(Citation: CrowdStrike PIONEER KITTEN August 2020)(Citation: CISA AA20-259A Iran-Based Actor September 2020)
- [10]RUBIDIUM
(Citation: Microsoft Threat Actor Naming July 2023)
- [11]UNC757
(Citation: CISA AA20-259A Iran-Based Actor September 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)
- [12]mitre-attackG0117Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
