CopyKittens__2015__CopyKittens.pdf
ID: a96eabb1-215a-4d04-9d5e-8607d8ad5b8d
STIX ID: report--a96eabb1-215a-4d04-9d5e-8607d8ad5b8d
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2015-11-23
Last Modified Date: 2015-11-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** This report analyzes a mid-level APT tracked as "CopyKittens" that uses spear-phishing lures to deliver a multi-stage Matryoshka framework (SCR dropper, reflective DLL loader, memory-resident RAT) with anti-analysis techniques and DNS-based command-and-control to exfiltrate data (including Outlook credentials) from Middle East diplomatic and academic targets, and provides IoCs (domains, IPs, hashes) and TTP details for detection and response.
