Pioneer Kitten
Named by CrowdStrikeSuspected state sponsor: Islamic Republic of IranPioneer Kitten is an IRGC-linked Iranian threat cluster active since at least 2017, known for rapidly exploiting VPN and network appliance vulnerabilities — including Pulse Secure, Fortinet, Citrix, and F5 — to gain widespread network access. The group operates a dual model: conducting state-directed espionage and selling network access to ransomware affiliates including ALPHV/BlackCat. The FBI and CISA formally attributed Pioneer Kitten to an Iranian government-linked entity in 2024. The cluster is tracked as Fox Kitten (ClearSky), Parisite (CrowdStrike), UNC757 (Mandiant), and Lemon Sandstorm (Microsoft).
Targeted Regions
AzerbaijanAzerbaijan
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
IsraelIsrael
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Middle EastMiddle East
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
United Arab EmiratesUnited Arab Emirates
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
United StatesUnited States
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020
Jan 2017 ~ Aug 2020 Jan 2019 ~ Sep 2020
Jan 2017 ~ Aug 2020 Jan 2019 ~ Sep 2020
Jan 2017 ~ Aug 2020 Jan 2019 ~ Sep 2020
Jan 2017 ~ Aug 2020 Jan 2019 ~ Sep 2020
Jan 2017 ~ Aug 2020 Jan 2019 ~ Sep 2020
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
Sep 2023 ~ Aug 2024
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.