Iranian nation-state actor known for disruptive ransomware and data leak operations against critical infrastructure.
Analyst brief
BANISHED KITTEN is an Iranian nation-state cyber threat actor active since 2008. It primarily targets government, healthcare, high-tech, and telecomms sectors in the US, Israel, the Middle East, and Europe. Key TTPs include disruptive ransomware attacks on Albanian government infrastructure in 2022, data leaks via the HomelandJustice persona, and use of the AllinOneNeo malware family against dissidents. Defenders must focus on ransomware and data exfiltration attempts against critical infrastructure, monitor C2 infrastructure with Iranian links, and account for data being stolen prior to destructive wiper deployment.
BANISHED KITTEN
DUNEStorm-0842Red Sandstorm
nation-state
BANISHED KITTEN is an Iranian state-nexus adversary active since at least 2008. While the adversary’s most prominent activity is the July and September 2022 disruptive attacks targeting Albanian government infrastructure and the use of the HomelandJustice persona to leak stolen data, BANISHED KITTEN has likely targeted dissidents using the AllinOneNeo malware family.
origin (suspected)
🇮🇷Iran· state-sponsoredattribution confidence: medium (50)