Fox Kitten
G01171 reportsaliases · Fox Kitten · UNC757 · Parisite · Pioneer Kitten · RUBIDIUM · Lemon Sandstorm
1
Reports
3
Techniques
3
Tactics
5
Countries
100%
Hunt coverage
6
Aliases
Analyst assessment — key judgments
- Signature techniques: T1588.006 (Vulnerabilities), T1021.007 (Cloud Services), T1589.001 (Credentials).
- Primary targeting: CN, RU, KP, IR.
- Newly emerged: 1 report(s) in last 30d vs 0 prior (+100%).
- Recent movement: 3 new technique(s), 1 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 100% of 3 observed techniques (0 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Newly emergedLast 30d: 1 vs 0 prior (+100%)· first reported 2026-08-26 · last 2026-08-26
0
7d
1
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
New techniques
T1588.006T1021.007T1589.001Targeting gained
CNIRKPRUUSNew infrastructure
https://connect.tenable.com/category/newVulnerabilities in this actor's reporting · 14
- CVE-2023-42793KEV1 rpt
- CVE-2024-24919KEV1 rpt
- CVE-2024-3400KEV1 rpt
- CVE-2024-47575KEV1 rpt
- CVE-2024-8190KEV1 rpt
- CVE-2024-8963KEV1 rpt
- CVE-2025-59718KEV1 rpt
- CVE-2026-1281KEV1 rpt
- CVE-2026-1340KEV1 rpt
- CVE-2026-15409KEV1 rpt
- CVE-2026-24858KEV1 rpt
- CVE-2023-341241 rpt
- CVE-2023-341321 rpt
- CVE-2023-341331 rpt
Overview
Analyst triage
Intelligence summary
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)(Citation: Dragos PARISITE )(Citation: ClearSky Pay2Kitten December 2020)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1588.006 · Vulnerabilitiesconf 601
- T1021.007 · Cloud Servicesconf 601
- T1589.001 · Credentialsconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|