CopyKittens Cyber Espionage Targets Israeli Diplomats and Researchers
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Spyware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
ClearSky and Minerva Labs' November 2015 report exposed CopyKittens, characterizing them as a "mid-level" group that assembled their attack platform largely from public code repositories — hence the name. The campaign targeted high-ranking Israeli diplomats at the Ministry of Foreign Affairs (including an Israeli ambassador in a large eastern European country) and Israeli academic researchers specializing in Middle East Studies. Three spearphishing waves were observed in 2015, using carefully tailored email subjects such as "Registration form to the United Nations CTITF," "Israeli MFA questionnaire – URGENT," and "Israel Ministry of Foreign Affairs Diplomatic List." Attachments were Word documents containing OLE-embedded SCR executables whose filenames used the RTLO Unicode character (U+202E) to display as PDFs (e.g., Quest__fdp.scr displayed as Quest__rcs.pdf). The Matryoshka framework operated in four stages: (1) the SCR dropper unpacked the reflective loader, signaled the C2 by downloading a PNG image, and ran a modified Pafish sandbox check — returning numeric codes 1–27 for detected artifacts and reporting back before terminating if analysis was detected; (2) the reflective loader used Stephen Fewer's Reflective DLL Injection to inject the RAT library into a legitimate running process without writing it to disk; (3) the RAT component established persistence via a registry Run key ({0355F5D0-467C-30E9-894C-C2FAEF522A13} under CurrentVersion\Run pointing to kernel.dll via rundll32.exe) and a scheduled task named "Microsoft Boost Kernel Optimization" running every 20 minutes; (4) C2 communication occurred over DNS, with queries obfuscated using a substitution cipher and data encoded in subdomains — responses used IP addresses from Microsoft and McAfee address blocks to lower SOC suspicion. The RAT's capabilities included Outlook password theft (specific IP response 134.170.185.13 triggered this), screen capture, and keylogging — all assembled from public forum code. All three C2 IPs were hosted at XLHost.com.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Ministry of Foreign Affairs of Israel The Israeli Ministry of Foreign Affairs is one of the most important ministries in the Israeli government. The ministry's role is to implement Israel's foreign policy, and promote economic, cultural, and scientific relations with other countries. Ministry of Foreign Affairs of Israel has been targeted by CopyKittens as the main target. | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | University | Verified |
| Region | Israel | Verified |
Extracted IOCs
- alhadath[.]mobi
- big-windowss[.]com
- cacheupdate14[.]com
- fbstatic-akamaihd[.]com
- fbstatic-a[.]space
- fbstatic-a[.]xyz
- gmailtagmanager[.]com
- haaretz[.]link
- haaretz-news[.]com
- heartax[.]info
- kernel4windows[.]in
- micro-windows[.]in
- mswordupdate15[.]com
- mswordupdate16[.]com
- mswordupdate17[.]com
- mywindows24[.]in
- patch7-windows[.]com
- patch8-windows[.]com
- patchthiswindows[.]com
- walla[.]link
- wethearservice[.]com
- wheatherserviceapi[.]info
- windowkernel[.]com
- windows-10patch[.]in
- windows24-kernel[.]in
- windows-drive20[.]com
- windows-india[.]in
- windowskernel14[.]com
- windows-kernel[.]in
- windowskernel[.]in
- windowslayer[.]in
- windows-my50[.]com
- windowssup[.]in
- windowsupup[.]com
- img.gmailtagmanager[.]com
- main.windowskernel14[.]com
- u.mywindows24[.]in
- 098e8dd0e874e59817f2e78cd48e58f3
- 0feb0b50b99f0b303a5081ffb3c4446d
- 1cef128513c05837f24796042b8e1cd9
- 1f9910cafe0e5f39887b2d5ab4df0d10
- 32261fe44c368724593fbf65d47fc826
- 38cb64ba0aafb86585d9bcbd1c500416
- 4765369d8ae52f2dd9b318e0c8b27054
- 577577d6df1833629bfd0d612e3dbb05
- 5e545dae692ecb4bddacdb9c526b1f16
- 6d8d0f7d73a9afaee667d71273e6e5e2
- 8734f46d932f179161042ef5b4a7b8a8
- 9853fc1f4d7ba23d728f4ee80842faf9
- 9db2719a3dde09ae260def9cd0d46dbe
- bad36581f72aa2d8597dd2b1bc7b2a7f
- bcf93595ba4586b6324963e989349319
- cfb4be91d8546203ae602c0284126408
- d2c117d18cb05140373713859803a0d6
- da529e0b81625828d52cd70efba50794
- f10135e03df18462c2e35eac13d61435
- 209[.]190.20.147
- 209[.]190.20.148
- 209[.]190.20.149
Tip: 59 related IOCs (3 IP, 37 domain, 0 URL, 0 email, 19 file hash) to this threat have been found.
Overlaps
Source: ClearSky - July 2017
Detection (11 cases): 209[.]190.20.149, 0feb0b50b99f0b303a5081ffb3c4446d, 1f9910cafe0e5f39887b2d5ab4df0d10, 32261fe44c368724593fbf65d47fc826, 577577d6df1833629bfd0d612e3dbb05, cfb4be91d8546203ae602c0284126408, d2c117d18cb05140373713859803a0d6, da529e0b81625828d52cd70efba50794, fbstatic-a[.]space, mywindows24[.]in, wethearservice[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions
ClearSky and Minerva Labs published the first public report on CopyKittens in November 2015, exposing a series of targeted cyberattacks against Israeli diplomats and academic researchers. The group sent spearphishing emails with carefully tailored subjects — such as UN counter-terrorism registration forms and Ministry of Foreign Affairs questionnaires — that contained Word documents hiding malicious executable files disguised as PDFs. Once opened, a multi-stage malware framework called Matryoshka silently installed itself, establishing remote access to the victim's computer and communicating back to the attackers via DNS traffic. Confirmed targets included a senior Israeli ambassador and researchers specializing in Middle East Studies.
CopyKittens' attribution remains unclear. ClearSky and Minerva Labs characterized them as a mid-level group, noting they assembled most of their attack tools from public code repositories rather than developing capabilities from scratch. The targeting of Israeli diplomats and Middle East Studies researchers aligns with the intelligence priorities of several state actors in the region. No definitive state sponsor was identified in the 2015 report, though subsequent CopyKittens reporting has strengthened the case for Iranian-linked origins based on tool overlaps and infrastructure indicators.
The primary goals were intelligence collection and data theft. The Matryoshka RAT gave the attackers persistent, silent access to victims' computers — capturing keystrokes, taking screenshots, and stealing Outlook email passwords. Targeting senior Israeli diplomats and Middle East Studies researchers would give an adversary insight into diplomatic communications, Israel's foreign policy positions, and academic analysis of regional politics — all high-value intelligence for any state actor with interests in the Middle East.
The campaign was tightly focused on Israel. Confirmed targets included senior diplomats at the Israeli Ministry of Foreign Affairs — including at least one ambassador posted in Eastern Europe — and Israeli academic researchers who specialize in Middle East Studies. The use of MFA-themed lures (questionnaires, diplomatic lists, UN counter-terrorism forms) indicates the attackers had prior knowledge of their targets' roles and routines, suggesting some degree of pre-attack research or earlier access.
Targets received spearphishing emails with Word documents attached. The documents contained hidden executable files — screensavers (.SCR) disguised as PDFs using a Unicode trick that reversed the filename characters so they appeared harmless. Opening the file silently ran the Matryoshka malware: first checking if the system was a security analysis environment, then injecting a remote access tool into a legitimate Windows process, and finally establishing covert communication with the attackers via DNS traffic. A decoy document was shown to the user to avoid suspicion.
Once installed, the Matryoshka RAT gave the attackers persistent, silent access to infected systems. They could record everything the victim typed, take screenshots of the desktop, steal saved email passwords from Outlook, and enumerate running processes. The malware communicated with the attackers using DNS — a protocol that many security tools don't monitor closely — and disguised its traffic using IP addresses from Microsoft and McAfee to make network alerts less likely.
Israeli diplomats and Middle East Studies researchers are high-value intelligence targets because they have direct access to sensitive foreign policy communications, diplomatic cables, and geopolitical analysis. For a state-aligned threat actor with interests in Israeli foreign policy — particularly regarding the broader Middle East — compromising these individuals could reveal negotiating positions, intelligence assessments, and internal government deliberations that would not otherwise be available through open sources.
Be suspicious of any email attachment — even from a seemingly known sender — that relates to government forms, diplomatic lists, or UN registrations. Never open .SCR files or enable macros in Word documents from unexpected sources. Organizations should block screensaver file extensions at the email gateway, monitor for DNS queries with unusually long or structured subdomain strings, and alert on rundll32.exe loading DLLs from non-standard locations. The full list of known CopyKittens domains and IP addresses should be blocked at the network perimeter.