An Iranian state-sponsored cyber espionage group targeting government entities across the Middle East and the West.
Analyst brief
CopyKittens is an Iranian state-sponsored cyber espionage group active since at least 2013. It primarily targets government, private sector, and civil society organizations in Israel, Saudi Arabia, Germany, and the United States. The group leverages tools like Cobalt Strike, TDTESS, Matryoshka malware, and Empire, using PowerShell for execution and Rundll32 with Code Signing for stealth. Defenders should focus on monitoring for unusual PowerShell activity, custom data archiving for exfiltration, and phishing campaigns targeting Middle Eastern entities.
CopyKittens
Slayer KittenG0052
nation-state
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.
origin (suspected)
🇮🇷Iran· state-sponsoredattribution confidence: medium (50)
Monitor the use of code signing certificates to detect abuse of signing certificates.
FAQ2
Which country is the origin of the CopyKittens group and what are its primary targets?+
CopyKittens is an Iranian cyber espionage group primarily targeting government, private sector, and civil society organizations in Israel, Saudi Arabia, Germany, the United States, Turkey, and Jordan.
What malware tools does CopyKittens use?+
The group uses Cobalt Strike, TDTESS, Matryoshka malware, and Empire, leveraging PowerShell for execution and Rundll32 with Code Signing techniques for stealth.