Threats Feed|Ferocious Kitten|Last Updated 24/07/2026|AuthorCertfa Radar|Publish Date16/06/2021

Ferocious Kitten APT Targets Iranian Users with Sophisticated MarkiRAT Malware

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Dropper,Keylogger,Malicious Macro,Malware,RAT,Baiting,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: Low Impact/High Probability

Threat Overview

Ferocious Kitten, an APT group active since 2015, primarily targets Persian-speaking individuals in Iran using weaponized documents. The attack involves malicious macros in documents, such as “Romantic Solidarity With Lovers of Freedom2.doc”, to drop executables that display anti-regime messages. These executables, once enabled, ensure persistence by placing themselves in the startup directory. The group's malware, MarkiRAT, exhibits capabilities like process checking, logging keystrokes, hijacking Telegram installations, and communicating with a C2 server. It specifically targets security solutions like Kaspersky and Bitdefender, indicating a high level of sophistication and focus on evading detection.

Detected Targets

TypeDescriptionConfidence
RegionIran
Verified

Extracted IOCs

  • com-view[.]space
  • updatei[.]com
  • aparat.com-view[.]space
  • khabarfarsi.com-view[.]org
  • 1fe34d84a058156296e86888ddd5cac9
  • 254a065a2c9cf8ff6bdd98ec120b3222
  • 3d6d731f03a0fcf4db9506ff9bdb7231
  • 4f1c9411739f7d3e5e418d4cd264e9a3
  • 5b4b42a8a730fae1b786326f27613da4
  • 61da1a5fa3d0d4e69a9ea6af53a91e45
  • 6747e3953775fb226da0723a94490fdb
  • 698201f289110a6dcff75407ab02e917
  • 7c83ec6d8459ac989669899071f41ae1
  • 8187b9a9af3eb78ee3b1190bb1db967e
  • 91ebde892ed57f19c0cbab98d04648ce
  • b0632b202eb5d204df112e1b5bac3f21
  • b2fe8c3ba2b9639f34c1727d50c4918d
  • c888f680b9bc3aabf0ec1cdd312436b5
  • ce5a7612892f27299362ae0569507e04
  • d22d9ce61e6aea72aa9a8a233530db43
  • e43e11b074fa7b071dec9bc294e0f95c
  • f9509755c5781f87788ffdf9efad075d
  • 1b9908cec557879382b63f071ec710be5b68ee79
  • 397c359064c5282276b7717731a6fdb998c31a0f
  • 3e30d4da7aa25ca8d44851848b05eff758ceeb46
  • 4c33552788239dcf044cddee51d2000f04509fc1
  • 609d4099ca91a494b22738e2050dd8cf12c61917
  • 736331c23d1813278c458b5ea8334ab14511afa6
  • 83e00f2e844795606b90c314495e91932b14f863
  • 93ae9778e55764f05e7d637e10a0d77ec3f6f6f7
  • 9923473c594ff12904e37a2405f619a7dc98d905
  • 9bcf60f1c806947dbbb0729f2e07496abe1b47b7
  • a1dd1aee6bb3ee3f8c3cee08955f3285c4e95439
  • a7f6963929a5709a841de71d99efb1f91cf31f8e
  • b59910f3ad87010140100ea63b9a474136bb5a97
  • b7b6345d9107cf7997646f3b04ed423c1271d070
  • b831c659335f669f7c2b48abe281f066be75d7af
  • c2e9eae6f870737dd4b6a6057bac35ff7cc5e244
  • f37003a6b6896d233a019e0e672fd9e92d261fc0
  • ffb76c958c1b53af09913c268c8e90f873d53f1a
  • 1e21645147aa4eac33495aa1713ffa30def0758f810ca944580a14be2828643d
  • 274beb57ae19cbc5c2027e08cb2b718dea7ed1acb21bd329d5aba33231fb699d
  • 2e8288c4603a04281127055b749e246abfd7f6b0f261bff96a47959dcae4ee39
  • 3a4ef9b7bd7f61c75501262e8b9e31f9e9bc3a841d5de33dcdeb8aaa65e95f76
  • 3c94eba2e2b73b2d2230a62e4513f457933d4668221992c71c847b79ba12f352
  • 405deb3a129df7b56357966b723a14c0aa9bc3615e2a20fccd7d2b5a8ceab30d
  • 489b895ad66f13c2a4ffeb218e735cace2b23d36fa55cd07b7edb4fbc03048cb
  • 54bd9fe21289fac0d48cc388aa35ecdc854d8c81865564dcb21fc1d73d22b86b
  • 636fee51245685de8f85d2d8af1dd1351267dbb9f9e571685a76d3894ed931da
  • 7699c50e8fed564b83fb0996e700fe51900e4f67cec4e669ed431e6a6f120865
  • a7c25d943f8b8689b4a55771349dd7b746fec094e5cc3f693c90801560a1808c
  • ab3e9f65c60c1760afc99629caee7fab8dba117a16a7f9f843ec43617e824b0d
  • b71c87ad8a0d179fc317656b339a57f2775b773c0fc54ea2b0b8d171b7af7a8a
  • ba300a293cc4bc39dd9d40a3c53ece51ac80af053175361d83d6ecb8735c45af
  • d723b7c150427a83d8a08dc613f68675690fa0f5b10287b078f7e8d50d1a363f
  • e7986cd2d31edd7ccb872dc1f0f745be6a483676ce0291f3c88b94b0e2306ea0
  • ec7196e98b7990b69ed58f49e5a87d1fda8bf81eb5cd7eeb9176f6e96a754403
  • fa9c0e0cb88b34d51deb257639314cf54cb11f9867a27579521681a2e17da4c4
  • hxxp://updatei[.]com/ddd/classes.dex
  • hxxp://updatei[.]com/hr.apk
download

Tip: 60 related IOCs (0 IP, 4 domain, 2 URL, 0 email, 54 file hash) to this threat have been found.

Overlaps

Ferocious KittenOperation MKLG: Persistent Cyber-Espionage Campaign in the Middle East

Source: QiAnXin - March 2021

Detection (two cases): 8187b9a9af3eb78ee3b1190bb1db967e, e43e11b074fa7b071dec9bc294e0f95c

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Ferocious Kitten Campaign

An attack campaign was uncovered involving malicious documents that secretly install a spying tool called MarkiRAT. Attackers use deceptive messages to trick users into enabling the content required to deploy the malware.

An Advanced Persistent Threat (APT) group known as Ferocious Kitten is responsible for this activity. This group has been actively conducting operations since at least 2015.

The primary goal of this attack is device compromise and data theft. The attackers use the malware to log keystrokes, steal passwords, and hijack communication applications.

The attacks are part of a targeted campaign rather than a widespread, global issue. The threat actors have been active over several years, evolving their delivery methods from direct programs to decoy documents.

Yes, the campaign specifically targets Persian-speaking individuals who appear to be located in Iran. The attackers frequently utilize anti-regime political messages to lure these specific users.

Attackers send documents containing hidden code that installs malware when opened and enabled by the user. This malware hides on the system, tracks what the user types, and can even disguise itself as the Telegram application to avoid detection.

The targeted individuals are likely of interest due to their political views or activities. The attackers deliberately use messages opposing the Iranian regime to trick these specific users into opening the malicious files.

Users should avoid opening unexpected documents and must not enable macros or hidden content when prompted. It is also highly recommended to verify that shortcuts for applications like Telegram have not been unexpectedly altered.

This is a highly targeted threat. It focuses specifically on Persian-speaking individuals in Iran rather than the general public.

About Affiliation
Ferocious Kitten
Ferocious Kitten is an Iranian-linked cyber espionage group active since at least 2015, first documented by Kaspersky in June 2021 after six years of undetected operation. Unlike most Iranian APTs targeting foreign governments, Ferocious Kitten focuses exclusively on Persian-speaking individuals inside Iran — including dissidents, activists, and opposition-linked targets — consistent with a domestic surveillance mission. The group delivers its custom MarkiRAT implant via spear phishing with politically themed decoy documents depicting anti-regime protests, along with backdoored versions of tools popular among Iranians such as the Psiphon VPN app. MarkiRAT provides keylogging, clipboard capture, screenshot collection, file upload and download, and arbitrary command execution over HTTP and HTTPS command and control. The group also developed specialized MarkiRAT variants that hijack Telegram and Chrome execution by replacing application shortcuts, enabling persistent access alongside legitimate apps. TTPs overlap with those of Domestic Kitten and Rampant Kitten, suggesting coordination within Iran's domestic surveillance apparatus.
View Ferocious Kitten's Insights