TRACER KITTEN is a likely Iran-based threat actor targeting telecoms in the EMEA region.
Analyst brief
TRACER KITTEN is a likely Iran-based threat actor. It targets telecommunications companies in the Europe, Middle East, and Africa (EMEA) region. Its key TTPs involve operating under valid user accounts, utilizing custom backdoors in combination with SSH tunnels for C2, conducting reconnaissance, credential harvesting, and preparing for data exfiltration. Defenders should focus on monitoring anomalous activity from legitimate accounts, especially unexpected SSH tunnelling and data staging behaviours.
TRACER KITTEN
unknown
In April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a telecommunications company in the Europe, Middle East and Africa (EMEA) region. The actor was found operating under valid user accounts, using custom backdoors in combination with SSH tunnels for C2. The adversary leveraged their foothold to conduct a variety of reconnaissance activities, undertake credential harvesting and prepare for data exfiltration.