Rampant Kitten
Named by Check PointSuspected state sponsor: Islamic Republic of IranRampant Kitten is a threat cluster documented by Check Point Research in 2020 as an extension of Domestic Kitten activity, with expanded capabilities targeting Iranian dissidents and opposition members. The group used a broader toolkit including Windows-based malware alongside mobile spyware, targeting members of the Mojahedin-e Khalq (MEK) opposition group and Iranian minority communities. Rampant Kitten operations included KeePass password manager credential theft, Telegram account takeover via fake desktop clients, and Android spyware deployment. The cluster shares the same Iranian state surveillance mission as Domestic Kitten, focusing on monitoring perceived regime threats inside and outside Iran.
Targeted Regions
AlbaniaAlbania
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
AzerbaijanAzerbaijan
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.