Domestic Kitten: An Iranian Surveillance Operation
概要
Chinese strategist Sun Tzu, Italian political philosopher Machiavelli and English philosopher Thomas Hobbes all justified deceit in war as a legitimate form of warfare. Preceding them all, however, were some in the Middle East who had already internalized and implemented this strategy to great effect, and continue to do so today.
Recent investigations by Check Point researchers reveal an extensive and targeted attack that has been taking place since 2016 and, until now, has remained under the radar due to the artful deception of its attackers towards their targets. Through the use of mobile applications, those behind the attack use fake decoy content to entice their victims to download such applications, which are in fact loaded with spyware, to then collect sensitive information about them. Interestingly, these targets include Kurdish and Turkish natives and ISIS supporters. Most interesting of all, though, is that all these targets are actually Iranians citizens.
Created: 2026-02-23
Indicators
Indicatorsは見つかっていない。
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 9.25
Matched TTPs:
- T1564.008 - Email Hiding Rules
- T1578 - Modify Cloud Compute Infrastructure
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 13.60
Matched TTPs:
- T1564.008 - Email Hiding Rules
- T1590.003 - Network Trust Dependencies
- T1102.003 - One-Way Communication
- T1547.002 - Authentication Package
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 9.08
Matched TTPs:
- T1682 - Query Public AI Services
- T1543.002 - Systemd Service
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1578 - Modify Cloud Compute Infrastructure
MITREへのリンク →
Score: 12.16
Matched TTPs:
- T1578 - Modify Cloud Compute Infrastructure
- T1586.003 - Cloud Accounts
- T1547.002 - Authentication Package
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 13.68
Matched TTPs:
- T1578 - Modify Cloud Compute Infrastructure
- T1491 - Defacement
- T1565.002 - Transmitted Data Manipulation
- T1588.005 - Exploits
MITREへのリンク →
Score: 13.15
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1218.010 - Regsvr32
- T1567.002 - Exfiltration to Cloud Storage
- T1578.001 - Create Snapshot
- T1569.002 - Service Execution
MITREへのリンク →
Score: 18.07
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1547.002 - Authentication Package
- T1218.010 - Regsvr32
- T1567.002 - Exfiltration to Cloud Storage
- T1578.001 - Create Snapshot
- T1547.008 - LSASS Driver
- T1569.002 - Service Execution
MITREへのリンク →
Score: 5.44
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1001 - Data Obfuscation
MITREへのリンク →
Score: 10.21
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1547.002 - Authentication Package
- T1578.001 - Create Snapshot
- T1569.002 - Service Execution
MITREへのリンク →
Score: 8.16
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1491 - Defacement
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 3.78
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 3.78
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 4.81
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 5.44
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1001 - Data Obfuscation
MITREへのリンク →
Score: 6.18
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1547.002 - Authentication Package
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 4.68
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1547.002 - Authentication Package
MITREへのリンク →
Score: 13.84
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1102.003 - One-Way Communication
- T1218.010 - Regsvr32
- T1567.002 - Exfiltration to Cloud Storage
- T1565.002 - Transmitted Data Manipulation
MITREへのリンク →
Score: 5.57
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1491 - Defacement
MITREへのリンク →
Score: 20.34
Matched TTPs:
- T1586.003 - Cloud Accounts
- T1021.006 - Windows Remote Management
- T1102.003 - One-Way Communication
- T1690 - Prevent Command History Logging
- T1565.002 - Transmitted Data Manipulation
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 7.51
Matched TTPs:
- T1586.003 - Cloud Accounts
- T1547.002 - Authentication Package
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 6.77
Matched TTPs:
- T1586.003 - Cloud Accounts
- T1001 - Data Obfuscation
MITREへのリンク →
Score: 7.13
Matched TTPs:
- T1491 - Defacement
- T1588.005 - Exploits
MITREへのリンク →
Score: 12.09
Matched TTPs:
- T1491 - Defacement
- T1102.003 - One-Way Communication
- T1578.001 - Create Snapshot
- T1569.002 - Service Execution
MITREへのリンク →
Score: 5.81
Matched TTPs:
- T1491 - Defacement
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 8.22
Matched TTPs:
- T1021.006 - Windows Remote Management
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 20.15
Matched TTPs:
- T1683.001 - Written Content
- T1102.003 - One-Way Communication
- T1001 - Data Obfuscation
- T1690 - Prevent Command History Logging
- T1547.002 - Authentication Package
- T1565.002 - Transmitted Data Manipulation
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1102.003 - One-Way Communication
MITREへのリンク →
Score: 4.65
Matched TTPs:
- T1001 - Data Obfuscation
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 4.65
Matched TTPs:
- T1001 - Data Obfuscation
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 7.86
Matched TTPs:
- T1690 - Prevent Command History Logging
- T1218.010 - Regsvr32
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 3.89
Matched TTPs:
- T1547.002 - Authentication Package
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 5.33
Matched TTPs:
- T1547.002 - Authentication Package
- T1569.002 - Service Execution
MITREへのリンク →
Score: 4.99
Matched TTPs:
- T1547.002 - Authentication Package
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 3.89
Matched TTPs:
- T1547.002 - Authentication Package
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 4.99
Matched TTPs:
- T1547.002 - Authentication Package
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 4.02
Matched TTPs:
- T1218.010 - Regsvr32
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 8.55
Matched TTPs:
- T1218.010 - Regsvr32
- T1592.002 - Software
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 5.45
Matched TTPs:
- T1565.002 - Transmitted Data Manipulation
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 5.12
Matched TTPs:
- T1578.001 - Create Snapshot
- T1547.008 - LSASS Driver
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.80
Matched TTPs:
- T1565.002 - Transmitted Data Manipulation
- T1547.002 - Authentication Package
- T1690 - Prevent Command History Logging
- T1683.001 - Written Content
- T1102.003 - One-Way Communication
- T1001 - Data Obfuscation
MITREへのリンク →
Score: 0.78
Matched TTPs:
- T1021.006 - Windows Remote Management
- T1565.002 - Transmitted Data Manipulation
- T1586.003 - Cloud Accounts
- T1690 - Prevent Command History Logging
- T1102.003 - One-Way Communication
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 0.73
Matched TTPs:
- T1569.002 - Service Execution
- T1590.003 - Network Trust Dependencies
- T1218.010 - Regsvr32
- T1547.002 - Authentication Package
- T1578.001 - Create Snapshot
- T1547.008 - LSASS Driver
- T1567.002 - Exfiltration to Cloud Storage
MITREへのリンク →
Score: 0.63
Matched TTPs:
- T1565.002 - Transmitted Data Manipulation
- T1590.003 - Network Trust Dependencies
- T1218.010 - Regsvr32
- T1102.003 - One-Way Communication
- T1567.002 - Exfiltration to Cloud Storage
MITREへのリンク →
Score: 0.59
Matched TTPs:
- T1578 - Modify Cloud Compute Infrastructure
- T1547.002 - Authentication Package
- T1586.003 - Cloud Accounts
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 0.59
Matched TTPs:
- T1590.003 - Network Trust Dependencies
- T1218.010 - Regsvr32
- T1547.002 - Authentication Package
- T1564.008 - Email Hiding Rules
- T1102.003 - One-Way Communication
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1578 - Modify Cloud Compute Infrastructure
- T1588.005 - Exploits
- T1565.002 - Transmitted Data Manipulation
- T1491 - Defacement
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1569.002 - Service Execution
- T1590.003 - Network Trust Dependencies
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
- T1567.002 - Exfiltration to Cloud Storage
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る