logo

CopyKittens__2015__CopyKittens.pdf

ID: a96eabb1-215a-4d04-9d5e-8607d8ad5b8d

STIX ID: report--a96eabb1-215a-4d04-9d5e-8607d8ad5b8d

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2015-11-23

Last Modified Date: 2015-11-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** This report analyzes a mid-level APT tracked as "CopyKittens" that uses spear-phishing lures to deliver a multi-stage Matryoshka framework (SCR dropper, reflective DLL loader, memory-resident RAT) with anti-analysis techniques and DNS-based command-and-control to exfiltrate data (including Outlook credentials) from Middle East diplomatic and academic targets, and provides IoCs (domains, IPs, hashes) and TTP details for detection and response.