CopyKittens: Espionage Campaign Targeting Strategic Sectors Across the Globe
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Operation Wilted Tulip, jointly published by ClearSky and Trend Micro in July 2017, exposes CopyKittens' full espionage apparatus active since 2013. The group targeted government institutions (including Ministries of Foreign Affairs), academic institutions, defense companies, IT companies, and media outlets across Israel, Saudi Arabia, Turkey, the US, Jordan, and Germany — with UN employees also targeted. Five delivery methods were documented: watering hole attacks inserting BeEF (Browser Exploitation Framework) JavaScript into breached news websites (Jerusalem Post, Maariv, IDF Disabled Veterans Organization); web-based exploitation using browser fingerprinting code served from attacker-built sites after compromising email accounts at target organizations; malicious documents exploiting CVE-2017-0199 (Word/HTA RCE), embedding OLE objects with RTLO (right-to-left override) extension spoofing, and macro-based execution; fake Facebook profiles and a fake Israeli news aggregator ("Emet press," built on NovinWebGostar — an Iranian web development platform) to build target trust; and SQL injection via Havij, sqlmap, and Acunetix against internet-facing web servers. Custom malware included TDTESS backdoor, Matryoshka v1/v2 RAT, Vminst (lateral movement tool injecting Cobalt Strike via stolen credentials), NetSrv (Cobalt Strike loader), and ZPP (file compressor for exfiltration). Public tools used include Cobalt Strike (trial version), Metasploit, Mimikatz, and Empire. DNS tunneling was the primary C2 channel in both Cobalt Strike and Matryoshka. A shared AI Squared digital certificate found in CopyKittens samples had also been used by OilRig, suggesting possible resource sharing or collaboration between the two groups. A developer username "shiranz" appeared in metadata of multiple samples, providing a consistent attribution artifact.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Disabled Veterans IDF Organization The disabled Veterans IDF Organization (The Israeli Defense Force Disabled Veterans Organization) was founded in 1949 and became the main body in Israel, which provides a full aid envelope for all soldiers, troops and security forces who were injured or sick during their service. Disabled Veterans IDF Organization has been targeted by CopyKittens as the main target. | Verified |
| Case | Maariv Maariv is a Hebrew-language daily newspaper published in Israel. From Sunday to Thursday, it is printed under the Ma'ariv Hashavu'a brand, while the weekend edition that is out on Friday is called Ma'ariv SofHashavu'a. Maariv has been targeted by CopyKittens as the main target. | Verified |
| Case | The Jerusalem Post The Jerusalem Post is a broadsheet newspaper based in Jerusalem, founded in 1932 during the British Mandate of Palestine by Gershon Agron as The Palestine Post. In 1950, it changed its name to The Jerusalem Post. The Jerusalem Post has been targeted by CopyKittens as the main target. | Verified |
| Sector | Defense | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Information Technology | Verified |
| Sector | Media | Verified |
| Region | Germany | Verified |
| Region | Israel | Verified |
| Region | Jordan | Verified |
| Region | Saudi Arabia | Verified |
| Region | Turkey | Verified |
| Region | United States | Verified |
Exploited Vulnerabilities
Extracted IOCs
- 1m100[.]tech
- ads-youtube[.]net
- akamaitechnology[.]tech
- alkamaihd[.]com
- broadcast-microsoft[.]tech
- cachevideo[.]com
- cloudflare-analyse[.]com
- cloudflare-statics[.]com
- cortana-search[.]com
- digicert[.]online
- dnsserv[.]host
- fbstatic-a[.]space
- fdgdsg[.]xyz
- israelnewsagency[.]link
- microsoft-office[.]solutions
- mywindows24[.]in
- nameserver[.]win
- newsfeeds-microsoft[.]press
- nsserver[.]host
- owa-microsoft[.]online
- sharepoint-microsoft[.]co
- ssl-gstatic[.]online
- symcd[.]xyz
- terendmicro[.]com
- update5x[.]zip
- updatedrivers[.]org
- wethearservice[.]com
- winfeedback[.]net
- winupdate64[.]com
- winupdate64[.]org
- a104-93-82-25.mandalasanati[.]info
- api.02ac36110.49318.a.gtld-servers[.]zone
- code.jguery[.]net
- doa.stage.7338879.i.gtld-servers[.]services
- ea-in-f155.1e100.microsoft-security[.]host
- fda.stage.7338879.i.gtld-servers[.]services
- fetchnews-agency.news-bbc[.]press
- files0.terendmicro[.]com
- iba.stage.7338879.i.gtld-servers[.]services
- img.twiter-statics[.]info
- js.jguery[.]net
- msv-updates.gsvr-static[.]co
- pht.is.nlb-deploy.edge-dyn.e11.f20.ads-youtube[.]online
- qqa.stage.7338879.i.gtld-servers[.]services
- rqa.stage.7338879.i.gtld-servers[.]services
- s1w-amazonaws.office-msupdate[.]solutions
- ssl.pmo.gov.il-dana-naauthurl1-welcome.cgi.primeminister-goverment-techcenter[.]tech
- update.microsoft-office[.]solutions
- 0de9c5c6599fdf5201599ff9b30e0000
- 0feb0b50b99f0b303a5081ffb3c4446d
- 113ca319e85778b62145019359380a08
- 1ca03f92f71d5ecb5dbf71b14d48495c
- 1f9910cafe0e5f39887b2d5ab4df0d10
- 1fba1876c88203a2ae6a59ce0b5da2a1
- 217b1c2760bcf4838f5e3efb980064d7
- 32261fe44c368724593fbf65d47fc826
- 3676914af9fd575deb9901a8b625f032
- 3d2885edf1f70ce4eb1e9519f47a669f
- 3de91d07ac762b193d5b67dd5138381a
- 41466bbb49dd35f9aa3002e546da65eb
- 435a93978fa50f55a64c788002da58a5
- 4999967c94a2fb1fa8122f1eea7a0e02
- 4a3d93c0a74aaabeb801593741587a02
- 506415ef517b4b1f7679b3664ad399e1
- 577577d6df1833629bfd0d612e3dbb05
- 5e65373a7c6abca7e3f75ce74c6e8143
- 62652f074924bb961d74099bc7b95731
- 62f8f45c5f10647af0040f965a3ea96d
- 64c9acc611ef47486ea756aca8e1b3b7
- 6ea02f1f13cc39d953e5a3ebcdcfd882
- 720203904c9eaf45ff767425a8c518cd
- 752240cddda5acb5e8d026cef82e2b54
- 838fb8d181d52e9b9d212b49f4350739
- 871efc9ecd8a446a7aa06351604a9bf4
- 8b702ba2b2bd65c3ad47117515f0669c
- 8f77a9cc2ad32af6fb1865fdff82ad89
- 94ba33696cd6ffd6335948a752ec9c19
- 9846b07bf7265161573392d24543940e
- a4dd1c225292014e65edb83f2684f2d5
- a60a32f21ac1a2ec33135a650aa8dc71
- ac29659dc10b2811372c83675ff57d23
- b34721e53599286a1093c90a9dd0b789
- b571c8e0e3768a12794eaf0ce24e6697
- bcae706c00e07936fc41ac47d671fc40
- bd38cab32b3b8b64e5d5d3df36f7c55a
- bf23ce4ae7d5c774b1fa6becd6864b3b
- c5a02e984ca3d5ac13cf946d2ba68364
- cf8502b8b67d11fbb0c75ebcf741db15
- cfb4be91d8546203ae602c0284126408
- d2c117d18cb05140373713859803a0d6
- d3b9da7c8c54f7f1ea6433ac34b120a1
- d9aa197ca2f01a66df248c7a8b582c40
- da529e0b81625828d52cd70efba50794
- e319f3fb40957a5ff13695306dd9de25
- e37418ba399a095066845e7829267efe
- efca6664ad6d29d2df5aaecf99024892
- fb775e900872e01f65e606b722719594
- 07317545c8d6fc9beedd3dd695ba79dd3818b941
- 1c43ed17acc07680924f2ec476d281c8c5fd6b4a
- 1f867be812087722010f12028beeaf376043e5d7
- 341c920ec47efa4fd1bfcd1859a7fb98945f9d85
- 37449ddfc120c08e0c0d41561db79e8cbbb97238
- 3c0ecb46d65dd57c33df5f6547f8fffb3e15722d
- 59c448abaa6cd20ce7af33d6c0ae27e4a853d2bd
- 6a19624d80a54c4931490562b94775b74724f200
- 8968f439ef26f3fcded4387a67ea5f56ce24a003
- aba7771c42aea8048e4067809c786b0105e9dfaa
- b11aa089879cd7d4503285fa8623ec237a317aee
- eb01202563dc0a1a3b39852ccda012acfe0b6f4d
- f1607a5b918345f89e3c2887c6dafc05c5832593
- fa3d5d670dc1d153b999c3aec7b1d815cc33c4dc
- 02f2c896287bc6a71275e8ebe311630557800081862a56a3c22c143f2f3142bd
- 1072b82f53fdd9fa944685c7e498eece89b6b4240073f654495ac76e303e65c9
- 165f8db9c6e2ca79260b159b4618a496e1ed6730d800798d51d38f07b3653952
- 16a711a8fa5a40ee787e41c2c65faf9a78b195307ac069c5e13ba18bce243d01
- 2df6fe9812796605d4696773c91ad84c4c315df7df9cf78bee5864822b1074c9
- 32860b0184676509241bbaf9233068d472472c3d9c93570fc072e1acea97a1d4
- 4442c48dd314a04ba4df046dfe43c9ea1d229ef8814e4d3195afa9624682d763
- 55f513d0d8e1fd41b1417a0eb2afff3a039a9529571196dd7882d1251ab1f9bc
- 5fe0e156a308b48fb2f9577ed3e3b09768976fdd99f6b2d2db5658b138676902
- 73f14f320facbdd29ae6f0628fa6f198dc86ba3428b3eddbfc39cf36224cebb9
- 7651f0d886e1c1054eb716352468ec6aedab06ed61e1eebd02bca4efbb974fb6
- 7ad65e39b79ad56c02a90dfab8090392ec5ffed10a8e276b86ec9b1f2524ad31
- 7e3c9323be2898d92666df33eb6e73a46c28e8e34630a2bd1db96aeb39586aeb
- 8c8496390c3ad048f2a0a4031edfcdac819ee840d32951b9a1a9337a2dcbea25
- 8f6f7416cfdf8d500d6c3dcb33c4f4c9e1cd33998c957fea77fbd50471faec88
- 9e5ab438deb327e26266c27891b3573c302113b8d239abc7f9aaa7eff9c4f7bb
- a4adbea4fcbb242f7eac48ddbf13c814d5eec9220f7dce01b2cc8b56a806cd37
- acf24620e544f79e55fd8ae6022e040257b60b33cf474c37f2877c39fbf2308a
- afa563221aac89f96c383f9f9f4ef81d82c69419f124a80b7f4a8c437d83ce77
- b01e955a34da8698fae11bf17e3f79a054449f938257284155aeca9a2d3815dd
- bff115d5fb4fd8a395d158fb18175d1d183c8869d54624c706ee48a1180b2361
- 104[.]200.128.126
- 104[.]200.128.161
- 104[.]200.128.173
- 104[.]200.128.183
- 104[.]200.128.184
- 104[.]200.128.185
- 104[.]200.128.187
- 104[.]200.128.195
- 104[.]200.128.196
- 104[.]200.128.198
- 104[.]200.128.205
- 104[.]200.128.206
- 104[.]200.128.208
- 104[.]200.128.209
- 104[.]200.128.48
- 104[.]200.128.58
- 104[.]200.128.64
- 104[.]200.128.71
- 107[.]181.160.138
- 107[.]181.160.178
- 107[.]181.160.194
- 107[.]181.160.195
- 107[.]181.161.141
- 107[.]181.174.21
- 107[.]181.174.228
- 107[.]181.174.232
- 107[.]181.174.241
- 141[.]105.67.58
- 141[.]105.68.25
- 141[.]105.68.26
- 141[.]105.68.29
- 141[.]105.69.69
- 141[.]105.69.70
- 141[.]105.69.77
- 144[.]168.45.126
- 146[.]0.73.109
- 146[.]0.73.110
- 146[.]0.73.111
- 146[.]0.73.112
- 146[.]0.73.114
- 158[.]69.150.163
- 173[.]244.173.11
- 173[.]244.173.12
- 173[.]244.173.13
- 176[.]31.18.29
- 185[.]118.65.230
- 185[.]118.66.114
- 185[.]92.73.194
- 188[.]120.224.198
- 188[.]120.228.172
- 188[.]120.232.157
- 188[.]120.242.93
- 188[.]120.243.11
- 188[.]120.247.151
- 188[.]165.69.39
- 192[.]99.242.212
- 198[.]50.214.62
- 198[.]55.107.164
- 206[.]221.181.253
- 209[.]190.20.149
- 209[.]190.20.59
- 209[.]190.20.62
- 209[.]51.199.116
- 212[.]199.61.51
- 217[.]12.201.240
- 217[.]12.218.242
- 31[.]192.105.16
- 31[.]192.105.17
- 31[.]192.105.28
- 38[.]130.75.20
- 51[.]254.76.54
- 5[.]34.180.252
- 5[.]34.181.13
- 62[.]109.2.52
- 66[.]55.152.164
- 68[.]232.180.122
- 80[.]179.42.37
- 80[.]179.42.44
- 86[.]105.18.5
- 93[.]190.138.137
- a104-93-82-25.mandalasanati[.]info/ibpa
- hxxp://38[.]130.75.20/check[.]html
- hxxp://api.02ac36110.49318.a.gtld-servers[.]zone
- hxxp://doa.stage.7338879.i.gtld-servers[.]services
- hxxp://ea-in-f155.1e100.microsoft-security[.]host/
- hxxp://fda.stage.7338879.i.gtld-servers[.]services
- hxxp://fetchnews-agency.news-bbc[.]press/en/20170/pictures.doc
- hxxp://fetchnews-agency.news-bbc[.]press/omnews.doc
- hxxp://fetchnews-agency.news-bbc[.]press/pictures.html
- hxxp://files0.terendmicro[.]com/
- hxxp://iba.stage.7338879.i.gtld-servers[.]services
- hxxp://img.twiter-statics[.]info/i/658a6d6ae42a658a6d6ae42a/0de9c5c6599fdf5201599ff9b30e0000/6e24e58cfc94/icon.png
- hxxp://js.jguery[.]net/main.js
- hxxp://main.windowskernel14[.]com/spl/update5x.zip
- hxxp://pht.is.nlb-deploy.edge-dyn.e11.f20.ads-youtube[.]online/winini.exe
- hxxp://qqa.stage.7338879.i.gtld-servers[.]services
- hxxp://rqa.stage.7338879.i.gtld-servers[.]services
- hxxps://ea-in-f155.1e100.microsoft-security[.]host/mtqj
- hxxp://ssl.pmo.gov.il-dana-naauthurl1-welcome.cgi.primeminister-goverment-techcenter[.]tech/%d7%a1%d7%a7%d7%a8%20%d7%a9%d7%a0%d7%aa%d7%99.docx
- hxxp://update.microsoft-office[.]solutions/error.html
- hxxp://update.microsoft-office[.]solutions/license.doc
Tip: 233 related IOCs (80 IP, 48 domain, 21 URL, 0 email, 84 file hash) to this threat have been found.
Overlaps
Source: ClearSky - March 2017
Detection (29 cases): 185[.]118.65.230, 188[.]120.224.198, 188[.]120.228.172, 188[.]120.242.93, 188[.]120.243.11, 188[.]120.247.151, 212[.]199.61.51, 80[.]179.42.44, 86[.]105.18.5, hxxp://pht.is.nlb-deploy.edge-dyn.e11.f20.ads-youtube[.]online/winini.exe, hxxp://ssl.pmo.gov.il-dana-naauthurl1-welcome.cgi.primeminister-goverment-techcenter[.]tech/%d7%a1%d7%a7%d7%a8%20%d7%a9%d7%a0%d7%aa%d7%99.docx, 4a3d93c0a74aaabeb801593741587a02, 5e65373a7c6abca7e3f75ce74c6e8143, 64c9acc611ef47486ea756aca8e1b3b7, 871efc9ecd8a446a7aa06351604a9bf4, cf8502b8b67d11fbb0c75ebcf741db15, fb775e900872e01f65e606b722719594, 1m100[.]tech, broadcast-microsoft[.]tech, dnsserv[.]host, ea-in-f155.1e100.microsoft-security[.]host, fdgdsg[.]xyz, nameserver[.]win, newsfeeds-microsoft[.]press, owa-microsoft[.]online, pht.is.nlb-deploy.edge-dyn.e11.f20.ads-youtube[.]online, sharepoint-microsoft[.]co, ssl-gstatic[.]online, ssl.pmo.gov.il-dana-naauthurl1-welcome.cgi.primeminister-goverment-techcenter[.]tech
Source: DomainTools - March 2017
Detection (five cases): 212[.]199.61.51, 86[.]105.18.5, 5fe0e156a308b48fb2f9577ed3e3b09768976fdd99f6b2d2db5658b138676902, 7651f0d886e1c1054eb716352468ec6aedab06ed61e1eebd02bca4efbb974fb6, ssl.pmo.gov.il-dana-naauthurl1-welcome.cgi.primeminister-goverment-techcenter[.]tech
Source: ClearSky - November 2015
Detection (11 cases): 209[.]190.20.149, 0feb0b50b99f0b303a5081ffb3c4446d, 1f9910cafe0e5f39887b2d5ab4df0d10, 32261fe44c368724593fbf65d47fc826, 577577d6df1833629bfd0d612e3dbb05, cfb4be91d8546203ae602c0284126408, d2c117d18cb05140373713859803a0d6, da529e0b81625828d52cd70efba50794, fbstatic-a[.]space, mywindows24[.]in, wethearservice[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions about Operation Wilted Tulip and CopyKittens
Operation Wilted Tulip is the name given to CopyKittens' full espionage apparatus, documented in a joint July 2017 report by ClearSky and Trend Micro. CopyKittens, active since at least 2013, ran a broad campaign targeting government ministries, defense contractors, academic institutions, IT companies, and media organizations across Israel, Saudi Arabia, Turkey, the US, Jordan, and Germany. They used five attack methods simultaneously: watering hole attacks on breached news websites, spearphishing emails with malicious documents, browser exploitation via compromised email accounts, fake Facebook personas, and SQL injection against web servers. The campaign involved both custom malware and publicly available hacking tools.
CopyKittens is assessed to be an Iranian-linked threat actor. Several indicators point to Iranian origin: the "Emet press" fake news site was built using NovinWebGostar, an Iranian web development platform; Havij, a SQL injection tool distributed by the Iranian security company ITSecTeam, was part of their toolkit; and a digital certificate found in their malware samples had also been used by OilRig, another Iran-linked group. The campaign's primary targeting of Israel, Saudi Arabia, and Turkey aligns with Iranian geopolitical interests. No definitive state sponsor attribution has been publicly confirmed, but the cumulative evidence strongly points to an Iranian nexus.
The primary goal was intelligence collection and data exfiltration. Once inside a target network, CopyKittens moved laterally and indiscriminately exfiltrated large volumes of documents, spreadsheets, personal data files, configuration files, and databases. The group showed a pattern of getting "greedy" — infecting multiple computers within an organization at once, which often triggered defensive alerts and led to their discovery. The scale of infrastructure and the length of the campaign — spanning at least four years — confirms this was a sustained, systematic intelligence collection operation aligned with Iranian state interests.
The campaign was broad. Confirmed targeted countries include Israel, Saudi Arabia, Turkey, the United States, Jordan, and Germany, with occasional targeting of individuals in other countries and UN employees. ClearSky and Trend Micro estimated that at least a few hundred people had been infected across multiple organizations. Named victims include Jerusalem Post, Maariv, and the IDF Disabled Veterans Organization — all breached and used as watering hole platforms. Ministries of Foreign Affairs in 28+ countries received the CVE-2017-0199 spearphishing email sent from the compromised Northern Cyprus MFA account.
Primary targets were government institutions (particularly Ministries of Foreign Affairs), defense companies, academic institutions, large IT companies, and media outlets. The focus on foreign ministries and defense contractors is consistent with state-directed intelligence collection. IT companies were also attractive because breaching one could provide VPN access to their client organizations — in at least one documented case, CopyKittens did exactly that, using a breached IT company's VPN credentials to pivot into client networks.
CopyKittens used five methods simultaneously. First, they injected BeEF (Browser Exploitation Framework) JavaScript into breached news websites — serving malicious code only to specific target IP addresses visiting those sites. Second, they compromised email accounts at target organizations and replied to existing email threads with links to attacker-built sites that fingerprinted visitors' browsers before delivering exploits. Third, they sent spearphishing emails with malicious documents — some exploiting CVE-2017-0199 (a Word vulnerability allowing silent code execution), others using RTLO characters to make executable files appear to be PDFs, and others with VBA macros. Fourth, they built and maintained fake Facebook personas with thousands of followers over years, and a fake Israeli news aggregator ("Emet press"), to build trust with targets. Fifth, they used Havij, sqlmap, and Acunetix to scan and exploit vulnerabilities in internet-facing web servers at target organizations.
Israel, Saudi Arabia, Turkey, and Germany are all countries with geopolitical tensions with Iran, making their government communications, defense capabilities, and foreign policy decisions high-priority intelligence targets. Academic and research institutions produce knowledge relevant to Iran's security and technology interests. IT companies are attractive because compromising them can provide access to many downstream client organizations at once. Media outlets were primarily used as watering hole platforms rather than targeted for their own data — their high traffic from relevant communities made them useful delivery vehicles. The multi-year, multi-vector approach reflects a well-resourced, state-directed operation with sustained intelligence collection mandates across the region.
Patch CVE-2017-0199 immediately if not already done — it was exploited in multiple documented CopyKittens operations. Apply RTLO character detection in email gateways to catch executables disguised as documents. Be suspicious of any email that replies to an existing thread and contains a link — CopyKittens specifically used this thread-hijacking method after compromising email accounts. Train staff to verify unexpected links even in seemingly legitimate correspondences. For organizations with internet-facing web servers, harden against SQL injection and monitor for scanning patterns matching Havij and sqlmap signatures. Block DNS tunneling at the network perimeter and alert on high-volume DNS queries with unusual subdomain patterns. Monitor VPN access logs for anomalous connections, and consider any breached IT vendor a potential pivot point into your own network.