Actors Insights|Latest update04/07/2026

Rampant Kitten

Named by Check PointSuspected state sponsor: Islamic Republic of Iran

Rampant Kitten is a threat cluster documented by Check Point Research in 2020 as an extension of Domestic Kitten activity, with expanded capabilities targeting Iranian dissidents and opposition members. The group used a broader toolkit including Windows-based malware alongside mobile spyware, targeting members of the Mojahedin-e Khalq (MEK) opposition group and Iranian minority communities. Rampant Kitten operations included KeePass password manager credential theft, Telegram account takeover via fake desktop clients, and Android spyware deployment. The cluster shares the same Iranian state surveillance mission as Domestic Kitten, focusing on monitoring perceived regime threats inside and outside Iran.

First Seen:Dec 2014
Last Seen:Nov 2021
Indexed Reports:1
Public IOCs:286
also known as:
Rampant Kitten (Check Point)

Targeted Regions

Albania
AL
Albania
Albania
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Azerbaijan
AZ
Azerbaijan
Azerbaijan
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Dec 2014 ~ Sep 2020
Jan 2014Jun 2026

Targeted Sectors

DissidentPolitical

Recent Indexed Reports

  1. Public
    Rampant Kitten: Iranian Cyber Espionage Campaign Exposed

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.