AI-Coded Oppression: “RedKitten” Malware Targets Iranian Protesters
ID: 21b01252-6a0c-508f-968c-c6a29d71a6ab
STIX ID: report--21b01252-6a0c-508f-968c-c6a29d71a6ab
Feed Name: securityonline.info
Threat Score
HarfangLab identified "RedKitten," a Jan 2026 campaign targeting Iranian protesters and NGOs with malicious Excel spreadsheets that trigger hidden macros to install a modular C# surveillance implant (SloppyMIO); analysts found traces of LLM-assisted development and noted the operators use GitHub, Google Drive and Telegram for configuration and command-and-control, and assess the activity as aligned with Iranian state interests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
