Domestic_Kitten__2021__research.checkpoint.com-Domestic_Kitten_An_Inside_Look_at_the_Iranian_Surveillance_Operations.pdf
ID: 11871476-249f-40d3-bd9a-f1af5aeb49f0
STIX ID: report--11871476-249f-40d3-bd9a-f1af5aeb49f0
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-02-10
Last Modified Date: 2021-02-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Check Point Research details the 'Domestic Kitten' surveillance campaign (attributed to APT-C-50) that used the FurBall Android malware to target primarily Iranian citizens and diaspora from 2017 onward; the malware (derived from KidLogger) exfiltrates SMS, contacts, call logs, media, records audio/calls, tracks location and uses multiple social and blog-based lures, active C2 infrastructure (firmwaresystemupdate.com, appsoftupdate.com) and identified IPs and numerous repackaged APK covers.
