RedKitten
Named by HarfangLabSuspected state sponsor: Islamic Republic of IranRedKitten is a threat cluster identified by HarfangLab in January 2026, targeting human rights NGOs, activists, academics, and individuals documenting the Iranian government's crackdown on the Dey 1404 protests — a wave of civil unrest that began in late December 2025 following economic strikes in Tehran. The campaign uses emotionally charged shock lures — macro-enabled Excel spreadsheets falsely claiming to list protesters killed in Tehran — to deploy SloppyMIO, a C#-based modular backdoor. SloppyMIO uses GitHub as a dead drop resolver to retrieve steganographically hidden configuration data from images, fetches modular payloads from Google Drive, and uses the Telegram Bot API for command and control. HarfangLab assessed the VBA dropper and malware development show multiple signs of LLM-assisted coding, including AI-generated variable names and automated code comments. Attribution to an Iranian state actor is based on Farsi-language artifacts, targeting patterns, and TTP overlaps with Tortoiseshell and Nemesis Kitten. RedKitten is tracked as a distinct cluster without confirmed alignment to a previously named group.
Targeted Regions
NetherlandsNetherlands
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Oct 2025 ~ Jan 2026
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.