Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ CopyKittens

🌐CopyKittens

🌐 CopyKittens is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 8 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.

View full actor card → All threat actors MITRE ATT&CK group spec (G0052) ↗
14Use cases
0Articles
8Techniques
0IOCs

About this actor (MITRE)

[CopyKittens](https://attack.mitre.org/groups/G0052) is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.(Citation: ClearSky CopyKittens March 2017)(Citation: ClearSky Wilted Tulip July 2017)(Citation: CopyKittens Nov 2015)

Known aliases

CopyKittens

Top techniques

All other tracked techniques

Detection use cases (14)

CopyKittens (G0052) Matryoshka-style rundll32 DLL load from user-writable path chained to hidden PowerShell AI · profile S CopyKittens pre-exfil staging: scripted RAR/7-Zip multi-volume password-protected archive of collected data AI · profile SΣ Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) MITRE match Office app spawning script/LOLBin child process MITRE match Phishing-link click correlated to endpoint execution MITRE match PowerShell encoded / obfuscated command MITRE match 7zip CommandLine To SMB Share Path MITRE match Anomalous usage of 7zip MITRE match Cisco IOS XE Tunnel Interface Configuration MITRE match Cisco Secure Firewall - Connection to File Sharing Domain MITRE match Detect Renamed 7-Zip MITRE match Detect Renamed WinRAR MITRE match