Threats Feed|Imperial Kitten|Last Updated 11/05/2026|AuthorCertfa Radar|Publish Date09/11/2023

Imperial Kitten's Middle East Cyber Campaign: Transport and Tech Sectors Targeted

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Compromised Credentials,SQL injection,Vulnerability Exploitation,Malicious Macro,RAT,Phishing,Compromised software
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

CrowdStrike's investigation into Imperial Kitten's cyber activities reveals targeted cyberattacks and strategic web compromise (SWC) operations against transportation, logistics, and technology sectors, primarily in the Middle East. These attacks, spanning from early 2022 to 2023, involved the use of compromised websites, phishing, and malware like IMAPLoader and StandardKeyboard for initial access and persistence. Techniques such as SQL injection, the use of public exploits, and credential theft were employed. The operations leveraged tools like PAExec and NetScan for lateral movement and credential harvesting. IMPERIAL KITTEN also used custom malware and open-source tools for data exfiltration, with some utilizing Discord for command and control communications.

Detected Targets

TypeDescriptionConfidence
SectorInformation Technology
Verified
SectorLogistics
Verified
SectorTransportation
Verified
RegionIsrael
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • blackcrocodile[.]online
  • updatenewnet[.]com
  • link.mymana[.]ir
  • brodyheywood@yandex[.]com
  • d3nisharris@yandex[.]com
  • giorgosgreen@yandex[.]com
  • hardi.lorel@yandex[.]com
  • harri5on.patricia@yandex[.]com
  • itdep@update-platform-check[.]online
  • justin.w0od@yandex[.]com
  • leviblum@yandex[.]com
  • n0ah.harrison@yandex[.]com
  • office@update-platform-check[.]online
  • oliv.morris@yandex[.]com
  • 1605b2aa6a911debf26b58fd3fa467766e215751377d4f746189566067dd5929
  • 32c40964f75c3e7b81596d421b5cefd0ac328e01370d0721d7bfac86a2e98827
  • 3bba5e32f142ed1c2f9d763765e9395db5e42afe8d0a4a372f1f429118b71446
  • 5c945a2be61f1f86da618a6225bc9d84f05f2c836b8432415ff5cc13534cfe2e
  • 87ccd1c15adc9ba952a07cd89295e0411b72cd4653b168f9b3f26c7a88d19b91
  • 989373f2d295ba1b8750fee7cdc54820aa0cb42321cec269271f0020fa5ea006
  • b588058e831d3a8a6c5983b30fc8d8aa5a711b5dfe9a7e816fe0307567073aed
  • cc7120942edde86e480a961fceff66783e71958684ad1307ffbe0e97070fd4fd
  • d3677394cb45b0eb7a7f563d2032088a8a10e12048ad74bae5fd9482f0aead01
  • fa54988c11aa1109ff64a2ab7a7e0eeec8e4635e96f6c30950f4fbdcd2bba336
  • 103[.]105.49.108
  • 146[.]185.219.220
  • 146[.]185.219.97
  • 149[.]248.54.40
  • 162[.]252.175.48
  • 163[.]182.144.239
  • 185[.]105.0.84
  • 185[.]212.149.35
  • 185[.]220.206.251
  • 185[.]241.4.7
  • 185[.]253.72.206
  • 192[.]52.166.71
  • 192[.]71.27.150
  • 193[.]182.144.12
  • 193[.]182.144.120
  • 193[.]182.144.175
  • 193[.]182.144.239
  • 193[.]182.144.52
  • 194[.]62.42.243
  • 194[.]62.42.98
  • 195[.]20.17.14
  • 195[.]20.17.198
  • 217[.]195.153.114
  • 45[.]155.37.105
  • 45[.]155.37.140
  • 45[.]32.181.118
  • 45[.]81.226.38
  • 45[.]8.146.37
  • 45[.]93.82.109
  • 45[.]93.93.198
  • 51[.]81.165.110
  • 64[.]176.164.117
  • 64[.]176.165.229
  • 64[.]176.165.70
  • 64[.]176.171.141
  • 64[.]176.172.26
  • 74[.]119.192.252
  • 77[.]91.74.21
  • 77[.]91.74.230
  • 77[.]91.94.151
  • 82[.]166.160.20
  • 82[.]166.160.26
  • 83[.]229.81.175
  • 94[.]131.114.32
  • 95[.]164.18.234
  • 95[.]164.61.253
  • 95[.]164.61.254
download

Tip: 71 related IOCs (47 IP, 3 domain, 0 URL, 11 email, 10 file hash) to this threat have been found.

Overlaps

Yellow LidercYellow Liderc's Multi-Faceted Cyber Campaign Targets Global Industries

Source: PwC - October 2023

Detection (eight cases): 32c40964f75c3e7b81596d421b5cefd0ac328e01370d0721d7bfac86a2e98827, 87ccd1c15adc9ba952a07cd89295e0411b72cd4653b168f9b3f26c7a88d19b91, 989373f2d295ba1b8750fee7cdc54820aa0cb42321cec269271f0020fa5ea006, cc7120942edde86e480a961fceff66783e71958684ad1307ffbe0e97070fd4fd, d3677394cb45b0eb7a7f563d2032088a8a10e12048ad74bae5fd9482f0aead01, brodyheywood@yandex[.]com, hardi.lorel@yandex[.]com, leviblum@yandex[.]com

UnclassifiedIranian-backed APTs Target Aeronautical Sector: A Multi-Vector Attack

Source: Cybersecurity and Infrastructure Security Agency - September 2023

Detection (one case): 103[.]105.49.108

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

IMPERIAL KITTEN Cyberespionage Campaign

In October 2023, cybersecurity researchers investigated a series of cyberattacks utilizing compromised websites and customized malicious software. Attackers lured victims to these compromised sites or sent them malicious documents to steal data and establish unauthorized access to their internal networks.

The attacks have been attributed to IMPERIAL KITTEN, a threat actor operating out of Iran. Active since at least 2017, this group is suspected of being connected to the Islamic Revolutionary Guard Corps (IRGC) and frequently uses social engineering, like fake job recruitment offers, to trick their victims.

This campaign is a strategic cyberespionage operation designed to gather intelligence. The primary goal is to profile victim systems, steal sensitive data, and maintain long-term, hidden access by using malware that blends in with normal network traffic, such as standard email and chat applications.

The campaign is geographically focused on the Middle East. Based on the compromised websites and collected data, the attacks heavily prioritize organizations located in Israel.

Yes, the attackers specifically targeted the transportation, logistics, maritime, and technology sectors. They also occasionally target IT service providers to use them as a stepping stone to reach their ultimate, primary targets.

Attackers gained initial access by exploiting software vulnerabilities, using stolen VPN logins, or tricking users into opening malicious Excel files disguised as job applications. Once inside a network, they used scanning tools to move around, stole passwords, and installed custom tools that abused regular email accounts and chat apps to secretly send stolen data back to the attackers.

Organizations in these specific sectors likely hold valuable strategic, logistical, or technological data. Stealing this information fulfills the strategic intelligence requirements of the Iranian government and associated military operations.

Organizations should secure their remote access points like VPNs, apply software updates to fix known vulnerabilities, and monitor their networks for unexpected connections to email or chat services. Individuals should remain highly cautious of unsolicited job recruitment documents or emails that ask them to enable macros.

This is a highly targeted campaign rather than a widespread issue. The threat actors carefully select specific industries in the Middle East and actively profile website visitors to ensure they are only infecting their desired targets.

About Affiliation
Imperial Kitten
Imperial Kitten is an IRGC-linked Iranian threat cluster active since at least 2017, named by CrowdStrike. The group conducts espionage and strategic web compromise operations primarily targeting Israeli and Middle Eastern organizations in the transportation, logistics, maritime, defense, and technology sectors. It is characterized by job-recruitment phishing, SQL injection, stolen VPN credential abuse, and distinctive email-based (IMAP) command and control using malware families including IMAPLoader and Liderc. The cluster is also tracked as Tortoiseshell, TA456, Crimson Sandstorm, and Curium across the industry.
View Imperial Kitten's Insights