Pioneer Kitten's Multi-Sector Cyber Offensive in the United States
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Compromised Credentials,Vulnerability Exploitation,Backdoor
- Attack Complexity: High
- Threat Risk: High Impact/High Probability
Threat Overview
Pioneer Kitten (also tracked as UNC757), an Iran-based threat actor, has been conducting a sustained cyber offensive against US organizations across the IT, government, healthcare, financial, insurance, and media sectors since early 2019. The group gains initial access by exploiting known vulnerabilities in VPN appliances — primarily Pulse Secure (CVE-2019-11510), Citrix (CVE-2019-19781), and F5 BIG-IP (CVE-2020-5902). Once inside, the actor installs web shells for persistent access, uses tunneling tools including Ngrok, FRP, and Chisel to bypass network controls, and harvests credentials. What makes Pioneer Kitten unusual is its dual motivation: it collects intelligence in support of Iranian government priorities while also selling access to compromised US networks on criminal hacker forums. CISA flagged the actor's potential capability and intent to deploy ransomware on victim networks, elevating the threat beyond traditional espionage.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Information Technology | Verified |
| Sector | Insurance | Verified |
| Sector | Journalists | Verified |
| Sector | Medical | Verified |
| Region | United States | Verified |
Exploited Vulnerabilities
Extracted IOCs
- 07b5472d347d42780469fb2654b7fc54
- 14df2e509b6ee8deb3ce6ba3b88e3de0
- 18f2cf11b940a62d63fd757e20564ec6
- 1fb4a5b09d9141362ed994c8a99b3cf5
- 20d89fa1df155632fafb2c9fe1a6a038
- 26ef590b60778bfdd9bfcbb24d832f94
- 2801de31bb6a6306f169ef81e5589521
- 2e993dbff4bcb21d52aa1897a4e2604e
- 3a83cad860a688e1f40683142280a67b
- 3be9b7030389ad5e106f169fbe7b7458
- 750b1bf7269ffc5860166efa8af6b34e
- 82e6e545c9863ed9f0df1e78d2457d13
- 83b4ba5ffed3f61f2c3c07cbfb9e4645
- 8495abfd7356f75ad7006d2ab42d4bee
- 86ff3a53ecd56eaa856f8c7c28d0a8f1
- 8f9567ca566ab5f79081d5d17c79ee41
- 9f9a21c74d71b03386ee22a566a1170d
- abdb24e1a410aa5fba49a4d1fe6a21bb
- ac07005f06ac63e5b1b0c1cd15a7a060
- b3b1dea400464ab5dd55e44766357957
- c8bc262d7126c3399baaec3bee89d542
- cb5b712bb6ddf459a6a953c98373b5f6
- cb77191ad61291924938362fbb902f32
- ce868f9ed3ebd9036456da37749ab7b9
- d7b7a8c120b69166643ee05bf70b37e5
- dbd0e57bcdedc0733290c5195a01ad35
- dc8a91125f273090cd8d76e9e588a074
- de1cd1c54711544508d157214323af85
- e11f9350ced37173d1e957ffe7d659b9
- ecf88595c12869be20d521f1934da506
- f006061c21d3eee457ffe5e2c69cba8e
- fd6c1e1fbe93a6c1ae97da3ddc3a381f
- 10836bda2d6a10791eb9541ad9ef1cb608aa9905766c28037950664cd64c6334
- 134ef25d48b8873514f84a0922ec9d835890bda16cc7648372e014c1f90a4e13
- 17f5b6d74759620f14902a5cc8bba8753df8a17da33f4ea126b98c7e2427e79c
- 28bc161df8406a6acf4b052a986e29ad1f60cbb19983fc17931983261b18d4ea
- 2944ea7d0045a1d64f3584e5803cbf3a026bd0e22bdf2e4ba1d28c6ad9e57849
- 3b14d5eafcdb9e90326cb4146979706c85a58be3fc4706779f0ae8d744d9e63c
- 4a1fc30ffeee48f213e256fa7bff77d8abd8acd81e3b2eb3b9c40bd3e2b04756
- 51e9cadeab1b33260c4ccb2c63f5860a77dd58541d7fb0840ad52d0a1abedd21
- 547440bd037a149ac7ac58bc5aaa65d079537e7a87dc93bb92edf0de7648761c
- 553f355f62c4419b808e078f3f71f401f187a9ac496b785e81fbf087e02dc13f
- 55b9264bc1f665acd94d922dd13522f48f2c88b02b587e50d5665b72855aa71c
- 5e0457815554574ea74b8973fc6290bd1344aac06c1318606ea4650c21081f0a
- 8c9aeedeea37ee88c84b170d9cd6c6d83581e3a57671be0ba19f2c8a17bd29f3
- 913ee2b048093162ff54dca050024f07200cdeaf13ffd56c449acb9e6d5fbda0
- 99344d862e9de0210f4056bdf4b8045ab9eabe1a62464d6513ed16208ab068fc
- b36288233531f7ac2e472a689ff99cb0f2ac8cba1b6ea975a9a80c1aa7f6a02a
- b443032aa281440017d1dcc3ae0a70d1d30d4f2f2b3f064f95f285e243559249
- f7ddf2651faf81d2d5fe699f81315bb2cf72bb14d74a1c891424c6afad544bde
Tip: 50 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 50 file hash) to this threat have been found.
FAQs
Frequently Asked Questions About Pioneer Kitten's Multi-Sector Offensive in the United States
Since early 2019, an Iranian state-linked threat actor known as Pioneer Kitten (or UNC757) has been targeting US organizations across the IT, government, healthcare, financial, insurance, and media sectors. The group exploits unpatched vulnerabilities in popular VPN and remote access appliances to break into networks, then installs web shells and tunneling tools to maintain long-term access. In September 2020, CISA published an advisory formally attributing the activity and noting that the actor was also selling access to compromised networks on criminal hacker forums.
Since early 2019, an Iranian state-linked threat actor known as Pioneer Kitten (or UNC757) has been targeting US organizations across the IT, government, healthcare, financial, insurance, and media sectors. The group exploits unpatched vulnerabilities in popular VPN and remote access appliances to break into networks, then installs web shells and tunneling tools to maintain long-term access. In September 2020, CISA published an advisory formally attributing the activity and noting that the actor was also selling access to compromised networks on criminal hacker forums.
Pioneer Kitten is an Iranian state-linked cyber espionage actor, also tracked as UNC757 by Mandiant. CISA attributed the activity to an Iran-based group operating with both government intelligence collection priorities and independent financial motives. The group's practice of selling network access on criminal hacker forums is unusual for a state-sponsored actor and suggests at least partial financial self-interest alongside its espionage mission.
Pioneer Kitten operates with a dual objective. Its primary mission is intelligence collection in support of Iranian government priorities — targeting US government, defense, and critical sector organizations to gather sensitive data. At the same time, the group monetizes its access by selling footholds in compromised US networks to other threat actors on hacker forums. CISA also noted the actor's potential intent to deploy ransomware on victim networks, adding a third potential motive of financial extortion.
The campaign has been active since early 2019 and targets organizations exclusively in the United States. Confirmed sectors include information technology, government, healthcare, financial services, insurance, and media. The breadth of targeting — spanning both critical infrastructure and commercially sensitive sectors — reflects both the intelligence collection priorities of the Iranian government and the access-selling motive, since footholds in any high-value US network carry value on criminal markets.
Pioneer Kitten targets any US organization running unpatched VPN appliances or remote access infrastructure — particularly Pulse Secure, Citrix, and F5 BIG-IP devices. Government agencies, healthcare providers, IT companies, financial institutions, insurers, and media organizations are all confirmed targets. Any organization in these sectors that has not patched the relevant CVEs (CVE-2019-11510, CVE-2019-19781, CVE-2020-5902, CVE-2019-11539) and relies on internet-facing VPN or remote access appliances should consider themselves at risk.
Pioneer Kitten starts by scanning for vulnerable VPN and remote access appliances using Nmap and Angry IP Scanner, then exploits known CVEs to gain initial access. Once inside, the group installs multiple web shells (Tiny PHP, China Chopper, ChunkyTuna) for persistent backdoor access and deploys tunneling tools — Ngrok, Fast Reverse Proxy (FRP), and Chisel — to maintain communications through firewall restrictions. The actor then moves laterally using RDP, SSH, and SMB, harvests credentials via LSASS dumping and Kerberos ticket theft, collects data from local systems and network shares, and archives it for exfiltration. File deletion and masquerading techniques are used throughout to reduce the detection footprint.
US organizations in government, healthcare, and critical infrastructure hold sensitive data and network access that is valuable to Iranian intelligence services for geopolitical monitoring and strategic advantage. For the financial, IT, and media sectors, network access is valuable both for intelligence and as a commodity to sell on criminal markets — a US enterprise network with broad internal access commands significant value among ransomware affiliates and other threat actors willing to pay for pre-established footholds.
Patch immediately — prioritize CVE-2019-11510 (Pulse Secure), CVE-2019-19781 (Citrix), CVE-2020-5902 (F5 BIG-IP), and CVE-2019-11539. Enforce MFA on all VPN and remote access services to limit the impact of stolen credentials. Monitor for and block Ngrok, FRP, and Chisel in your environment, as these legitimate tunneling tools are consistently abused by this actor. Deploy file integrity monitoring on internet-facing servers to detect unauthorized web shell installation. Review network logs for the known indicators of compromise published in CISA advisory AA20-259A. Given the ransomware deployment risk, maintain tested offline backups and ensure incident response plans cover both espionage and destructive attack scenarios.