Ferocious Kitten
G01372 reportsaliases · Ferocious Kitten
2
Reports
12
Techniques
9
Tactics
4
Countries
62%
Hunt coverage
1
Aliases
Analyst assessment — key judgments
- Signature techniques: T1036 (Masquerading), T1593.001 (Social Media), AML.T0074 (Masquerading).
- Primary targeting: IR, US, IL, AE.
- Steady activity: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 62% of 13 observed techniques (5 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
SteadyLast 30d: 0 vs 0 prior (+0%)· first reported 2026-07-01 · last 2026-07-21
0
7d
0
30d
2
90d
2
All
0.2
Rpts/wk
Reporting timeline · 12 months
Overview
Analyst triage
Intelligence summary
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.(Citation: Kaspersky Ferocious Kitten Jun 2021)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1036 · Masqueradingconf 601
- T1593.001 · Social Mediaconf 601
- AML.T0074 · Masqueradingconf 601
- T1204.002 · Malicious Fileconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1574.014 · AppDomainManagerconf 601
- T1684 · Social Engineeringconf 601
- T1491 · Defacementconf 601
- T1087.004 · Cloud Accountconf 601
- T1136.003 · Cloud Accountconf 601
- T1589.001 · Credentialsconf 601
- T1684.001 · Impersonationconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|