Threats Feed
- Public
CopyKittens: Espionage Campaign Targeting Strategic Sectors Across the Globe
Operation Wilted Tulip, jointly published by ClearSky and Trend Micro in July 2017, exposes CopyKittens' full espionage apparatus active since 2013. The group targeted government institutions (including Ministries of Foreign Affairs), academic institutions, defense companies, IT companies, and media outlets across Israel, Saudi Arabia, Turkey, the US, Jordan, and Germany — with UN employees also targeted. Five delivery methods were documented: watering hole attacks inserting BeEF (Browser Exploitation Framework) JavaScript into breached news websites (Jerusalem Post, Maariv, IDF Disabled Veterans Organization); web-based exploitation using browser fingerprinting code served from attacker-built sites after compromising email accounts at target organizations; malicious documents exploiting CVE-2017-0199 (Word/HTA RCE), embedding OLE objects with RTLO (right-to-left override) extension spoofing, and macro-based execution; fake Facebook profiles and a fake Israeli news aggregator ("Emet press," built on NovinWebGostar — an Iranian web development platform) to build target trust; and SQL injection via Havij, sqlmap, and Acunetix against internet-facing web servers. Custom malware included TDTESS backdoor, Matryoshka v1/v2 RAT, Vminst (lateral movement tool injecting Cobalt Strike via stolen credentials), NetSrv (Cobalt Strike loader), and ZPP (file compressor for exfiltration). Public tools used include Cobalt Strike (trial version), Metasploit, Mimikatz, and Empire. DNS tunneling was the primary C2 channel in both Cobalt Strike and Matryoshka. A shared AI Squared digital certificate found in CopyKittens samples had also been used by OilRig, suggesting possible resource sharing or collaboration between the two groups. A developer username "shiranz" appeared in metadata of multiple samples, providing a consistent attribution artifact.
read more about CopyKittens: Espionage Campaign Targeting Strategic Sectors Across the Globe - Public
CopyKittens Targets Israeli Media and Palestinian Healthcare in Watering Hole Attacks
The Iranian threat agent CopyKittens compromised multiple Israeli websites, including the Jerusalem Post, and one Palestinian Authority website between October 2016 and January 2017. The attackers bought access to the server to gain the access, inserting a single line of Javascript into existing libraries. This enabled them to load further malicious Javascript from a domain they controlled, selectively targeting users based on their IP addresses. The malicious payload used was the BeEF Browser Exploitation Framework.
read more about CopyKittens Targets Israeli Media and Palestinian Healthcare in Watering Hole Attacks - Public
CopyKitten’s Spearphishing Attack on Israeli Ministry of Communications
CopyKitten, a known cyber-attack group, has launched a spearphishing campaign targeting the Israeli government’s Ministry of Communications. The investigation commenced with the identification of a suspicious domain that led to multiple related domains. One such domain closely mimicked the Israeli Prime Minister's SSL VPN login page and was used to drop a malicious Word document titled "Annual Survey.docx." This document had an embedded OLE object that communicated with a C2 server, signifying a well-planned attack. The campaign appears to be part of CopyKitten's ongoing activities against Israeli interests.
read more about CopyKitten’s Spearphishing Attack on Israeli Ministry of Communications - Public
CopyKittens Cyber Espionage Targets Israeli Diplomats and Researchers
ClearSky and Minerva Labs' November 2015 report exposed CopyKittens, characterizing them as a "mid-level" group that assembled their attack platform largely from public code repositories — hence the name. The campaign targeted high-ranking Israeli diplomats at the Ministry of Foreign Affairs (including an Israeli ambassador in a large eastern European country) and Israeli academic researchers specializing in Middle East Studies. Three spearphishing waves were observed in 2015, using carefully tailored email subjects such as "Registration form to the United Nations CTITF," "Israeli MFA questionnaire – URGENT," and "Israel Ministry of Foreign Affairs Diplomatic List." Attachments were Word documents containing OLE-embedded SCR executables whose filenames used the RTLO Unicode character (U+202E) to display as PDFs (e.g., Quest__fdp.scr displayed as Quest__rcs.pdf). The Matryoshka framework operated in four stages: (1) the SCR dropper unpacked the reflective loader, signaled the C2 by downloading a PNG image, and ran a modified Pafish sandbox check — returning numeric codes 1–27 for detected artifacts and reporting back before terminating if analysis was detected; (2) the reflective loader used Stephen Fewer's Reflective DLL Injection to inject the RAT library into a legitimate running process without writing it to disk; (3) the RAT component established persistence via a registry Run key ({0355F5D0-467C-30E9-894C-C2FAEF522A13} under CurrentVersion\Run pointing to kernel.dll via rundll32.exe) and a scheduled task named "Microsoft Boost Kernel Optimization" running every 20 minutes; (4) C2 communication occurred over DNS, with queries obfuscated using a substitution cipher and data encoded in subdomains — responses used IP addresses from Microsoft and McAfee address blocks to lower SOC suspicion. The RAT's capabilities included Outlook password theft (specific IP response 134.170.185.13 triggered this), screen capture, and keylogging — all assembled from public forum code. All three C2 IPs were hosted at XLHost.com.
read more about CopyKittens Cyber Espionage Targets Israeli Diplomats and Researchers