logo

Domestic_Kitten__2021__research.checkpoint.com-Domestic_Kitten_An_Inside_Look_at_the_Iranian_Surveillance_Operations.pdf

ID: 11871476-249f-40d3-bd9a-f1af5aeb49f0

STIX ID: report--11871476-249f-40d3-bd9a-f1af5aeb49f0

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2021-02-10

Last Modified Date: 2021-02-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Check Point Research details the 'Domestic Kitten' surveillance campaign (attributed to APT-C-50) that used the FurBall Android malware to target primarily Iranian citizens and diaspora from 2017 onward; the malware (derived from KidLogger) exfiltrates SMS, contacts, call logs, media, records audio/calls, tracks location and uses multiple social and blog-based lures, active C2 infrastructure (firmwaresystemupdate.com, appsoftupdate.com) and identified IPs and numerous repackaged APK covers.