5259
ID: 1d431445-1d8f-4b8a-89c7-fb51871bf1b3
STIX ID: report--1d431445-1d8f-4b8a-89c7-fb51871bf1b3
Threat Score
85/100
On 29 January 2026 HarfangLab published a report on a new Iranian state-sponsored espionage campaign named "RedKitten" that since December 2025 targeted regime-critical individuals abroad via WhatsApp, Instagram, and Telegram; attackers used phishing (fake WhatsApp verification codes and a counterfeit WhatsApp Web page with an attacker-controlled QR code) to fully compromise victims' WhatsApp accounts and access messages, browser data, camera, microphone, and location.
