Ferocious Kitten APT Targets Iranian Users with Sophisticated MarkiRAT Malware
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Dropper,Keylogger,Malicious Macro,Malware,RAT,Baiting,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: Low Impact/High Probability
Threat Overview
Ferocious Kitten, an APT group active since 2015, primarily targets Persian-speaking individuals in Iran using weaponized documents. The attack involves malicious macros in documents, such as “Romantic Solidarity With Lovers of Freedom2.doc”, to drop executables that display anti-regime messages. These executables, once enabled, ensure persistence by placing themselves in the startup directory. The group's malware, MarkiRAT, exhibits capabilities like process checking, logging keystrokes, hijacking Telegram installations, and communicating with a C2 server. It specifically targets security solutions like Kaspersky and Bitdefender, indicating a high level of sophistication and focus on evading detection.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Iran | Verified |
Extracted IOCs
- com-view[.]space
- updatei[.]com
- aparat.com-view[.]space
- khabarfarsi.com-view[.]org
- 1fe34d84a058156296e86888ddd5cac9
- 254a065a2c9cf8ff6bdd98ec120b3222
- 3d6d731f03a0fcf4db9506ff9bdb7231
- 4f1c9411739f7d3e5e418d4cd264e9a3
- 5b4b42a8a730fae1b786326f27613da4
- 61da1a5fa3d0d4e69a9ea6af53a91e45
- 6747e3953775fb226da0723a94490fdb
- 698201f289110a6dcff75407ab02e917
- 7c83ec6d8459ac989669899071f41ae1
- 8187b9a9af3eb78ee3b1190bb1db967e
- 91ebde892ed57f19c0cbab98d04648ce
- b0632b202eb5d204df112e1b5bac3f21
- b2fe8c3ba2b9639f34c1727d50c4918d
- c888f680b9bc3aabf0ec1cdd312436b5
- ce5a7612892f27299362ae0569507e04
- d22d9ce61e6aea72aa9a8a233530db43
- e43e11b074fa7b071dec9bc294e0f95c
- f9509755c5781f87788ffdf9efad075d
- 1b9908cec557879382b63f071ec710be5b68ee79
- 397c359064c5282276b7717731a6fdb998c31a0f
- 3e30d4da7aa25ca8d44851848b05eff758ceeb46
- 4c33552788239dcf044cddee51d2000f04509fc1
- 609d4099ca91a494b22738e2050dd8cf12c61917
- 736331c23d1813278c458b5ea8334ab14511afa6
- 83e00f2e844795606b90c314495e91932b14f863
- 93ae9778e55764f05e7d637e10a0d77ec3f6f6f7
- 9923473c594ff12904e37a2405f619a7dc98d905
- 9bcf60f1c806947dbbb0729f2e07496abe1b47b7
- a1dd1aee6bb3ee3f8c3cee08955f3285c4e95439
- a7f6963929a5709a841de71d99efb1f91cf31f8e
- b59910f3ad87010140100ea63b9a474136bb5a97
- b7b6345d9107cf7997646f3b04ed423c1271d070
- b831c659335f669f7c2b48abe281f066be75d7af
- c2e9eae6f870737dd4b6a6057bac35ff7cc5e244
- f37003a6b6896d233a019e0e672fd9e92d261fc0
- ffb76c958c1b53af09913c268c8e90f873d53f1a
- 1e21645147aa4eac33495aa1713ffa30def0758f810ca944580a14be2828643d
- 274beb57ae19cbc5c2027e08cb2b718dea7ed1acb21bd329d5aba33231fb699d
- 2e8288c4603a04281127055b749e246abfd7f6b0f261bff96a47959dcae4ee39
- 3a4ef9b7bd7f61c75501262e8b9e31f9e9bc3a841d5de33dcdeb8aaa65e95f76
- 3c94eba2e2b73b2d2230a62e4513f457933d4668221992c71c847b79ba12f352
- 405deb3a129df7b56357966b723a14c0aa9bc3615e2a20fccd7d2b5a8ceab30d
- 489b895ad66f13c2a4ffeb218e735cace2b23d36fa55cd07b7edb4fbc03048cb
- 54bd9fe21289fac0d48cc388aa35ecdc854d8c81865564dcb21fc1d73d22b86b
- 636fee51245685de8f85d2d8af1dd1351267dbb9f9e571685a76d3894ed931da
- 7699c50e8fed564b83fb0996e700fe51900e4f67cec4e669ed431e6a6f120865
- a7c25d943f8b8689b4a55771349dd7b746fec094e5cc3f693c90801560a1808c
- ab3e9f65c60c1760afc99629caee7fab8dba117a16a7f9f843ec43617e824b0d
- b71c87ad8a0d179fc317656b339a57f2775b773c0fc54ea2b0b8d171b7af7a8a
- ba300a293cc4bc39dd9d40a3c53ece51ac80af053175361d83d6ecb8735c45af
- d723b7c150427a83d8a08dc613f68675690fa0f5b10287b078f7e8d50d1a363f
- e7986cd2d31edd7ccb872dc1f0f745be6a483676ce0291f3c88b94b0e2306ea0
- ec7196e98b7990b69ed58f49e5a87d1fda8bf81eb5cd7eeb9176f6e96a754403
- fa9c0e0cb88b34d51deb257639314cf54cb11f9867a27579521681a2e17da4c4
- hxxp://updatei[.]com/ddd/classes.dex
- hxxp://updatei[.]com/hr.apk
Tip: 60 related IOCs (0 IP, 4 domain, 2 URL, 0 email, 54 file hash) to this threat have been found.
Overlaps
Source: QiAnXin - March 2021
Detection (two cases): 8187b9a9af3eb78ee3b1190bb1db967e, e43e11b074fa7b071dec9bc294e0f95c
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Ferocious Kitten Campaign
An attack campaign was uncovered involving malicious documents that secretly install a spying tool called MarkiRAT. Attackers use deceptive messages to trick users into enabling the content required to deploy the malware.
An Advanced Persistent Threat (APT) group known as Ferocious Kitten is responsible for this activity. This group has been actively conducting operations since at least 2015.
The primary goal of this attack is device compromise and data theft. The attackers use the malware to log keystrokes, steal passwords, and hijack communication applications.
The attacks are part of a targeted campaign rather than a widespread, global issue. The threat actors have been active over several years, evolving their delivery methods from direct programs to decoy documents.
Yes, the campaign specifically targets Persian-speaking individuals who appear to be located in Iran. The attackers frequently utilize anti-regime political messages to lure these specific users.
Attackers send documents containing hidden code that installs malware when opened and enabled by the user. This malware hides on the system, tracks what the user types, and can even disguise itself as the Telegram application to avoid detection.
The targeted individuals are likely of interest due to their political views or activities. The attackers deliberately use messages opposing the Iranian regime to trick these specific users into opening the malicious files.
Users should avoid opening unexpected documents and must not enable macros or hidden content when prompted. It is also highly recommended to verify that shortcuts for applications like Telegram have not been unexpectedly altered.
This is a highly targeted threat. It focuses specifically on Persian-speaking individuals in Iran rather than the general public.