Flying Kitten
Activity: defense and aerospace sectors, also interested in targeting entities in the oil/gas industry.
Flying Kitten is an Iranian nation-state actor targeting US defense, aerospace, and oil & gas sectors.
Flying Kitten is an Iranian nation-state threat actor primarily targeting the defense, aerospace, oil, and gas sectors in the United States, as well as Iranian internet activists. Their main TTPs include gaining initial access via spearphishing attachments or services, followed by credential harvesting from web browsers, keylogging, and using tools like sqlmap and Havij for exploitation. Defenders should focus on email security controls, user awareness against malicious attachments, and hardening web applications against SQL injection attacks.
Activity: defense and aerospace sectors, also interested in targeting entities in the oil/gas industry.
Monitor and block suspicious emails and attachments to detect initial access points.
Monitor file execution policies to detect and prevent execution of malicious files.
Harden browser security to protect credentials stored in web browsers.
Monitor user activity to detect and prevent keylogging.
Monitor network traffic to detect and block the transfer of tools used for command and control.
Flying Kitten relies on spearphishing attachment and spearphishing via service for initial access.
Flying Kitten primarily targets the defense, aerospace, oil, and gas sectors in the United States, as well as Iranian internet activists.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.