Actors Insights|Latest update04/07/2026

Parisite

Named by DragosSuspected state sponsor: Islamic Republic of Iran

Parisite is CrowdStrike's designation for the Iranian IRGC-linked threat cluster known as Pioneer Kitten. CrowdStrike documented Parisite conducting large-scale VPN vulnerability exploitation campaigns targeting government and critical infrastructure organizations, consistent with the broader Pioneer Kitten cluster's tradecraft. The group rapidly weaponizes newly disclosed CVEs in enterprise VPN products to gain initial access to target networks, then maintains persistence for both intelligence collection and access brokering to ransomware affiliates.

First Seen:Jan 2017
Last Seen:Aug 2024
Indexed Reports:0
Public IOCs:0
also known as:
Pioneer Kitten (CrowdStrike)Parisite (Dragos)UNC757 (Mandiant)Lemon Sandstorm (Microsoft)RUBIDIUM (Microsoft)Fox Kitten (ClearSky)G0117 (Mitre)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.