Actors Insights|Latest update04/07/2026

RedKitten

Named by HarfangLabSuspected state sponsor: Islamic Republic of Iran

RedKitten is a threat cluster identified by HarfangLab in January 2026, targeting human rights NGOs, activists, academics, and individuals documenting the Iranian government's crackdown on the Dey 1404 protests — a wave of civil unrest that began in late December 2025 following economic strikes in Tehran. The campaign uses emotionally charged shock lures — macro-enabled Excel spreadsheets falsely claiming to list protesters killed in Tehran — to deploy SloppyMIO, a C#-based modular backdoor. SloppyMIO uses GitHub as a dead drop resolver to retrieve steganographically hidden configuration data from images, fetches modular payloads from Google Drive, and uses the Telegram Bot API for command and control. HarfangLab assessed the VBA dropper and malware development show multiple signs of LLM-assisted coding, including AI-generated variable names and automated code comments. Attribution to an Iranian state actor is based on Farsi-language artifacts, targeting patterns, and TTP overlaps with Tortoiseshell and Nemesis Kitten. RedKitten is tracked as a distinct cluster without confirmed alignment to a previously named group.

First Seen:Oct 2025
Last Seen:Jan 2026
Indexed Reports:1
Public IOCs:12
Cluster: UnclassifiedMisp: RedKitten
also known as:
RedKitten

Targeted Regions

Netherlands
NL
Netherlands
Netherlands
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Jan 2025Dec 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.