Actors Insights|Latest update24/07/2026

Tracer Kitten

Named by CrowdStrikeSuspected state sponsor: Islamic Republic of Iran

Tracer Kitten is CrowdStrike's designation for an Iran-based cyber espionage actor active since at least 2016, with a suspected nexus to the Iranian government. The group likely fulfills Iranian intelligence requirements related to telecommunications entities in the Middle East and beyond. In April 2020, CrowdStrike Falcon OverWatch discovered Tracer Kitten conducting malicious interactive activity against multiple hosts at a telecommunications company in the Europe, Middle East and Africa (EMEA) region, operating under valid user credentials to evade detection. The group's activity is characterized by credential abuse, lateral movement using legitimate access tools, and focus on telecommunications intelligence — sectors of consistent strategic interest to Iranian state actors seeking to monitor regional communications infrastructure. Tracer Kitten's targeting profile and operational techniques align broadly with other IRGC-linked actors focused on telecommunications and critical communications infrastructure in the region.

First Seen:Apr 2020
Last Seen:Sep 2020
Indexed Reports:1
Public IOCs:0
also known as:
Tracer Kitten (CrowdStrike)

Targeted Regions

Europe
EU
Europe
Europe
Apr 2020 ~ Sep 2020
Apr 2020 ~ Sep 2020
Apr 2020 ~ Sep 2020
Middle East
ME
Middle East
Middle East
Apr 2020 ~ Sep 2020
Apr 2020 ~ Sep 2020
Apr 2020 ~ Sep 2020
Jan 2020Sep 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.