logo

Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists

ID: 97017495-a01d-5312-b43f-256d9b6772a2

STIX ID: report--97017495-a01d-5312-b43f-256d9b6772a2

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-01-31

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A Farsi-speaking, Iran-aligned actor (RedKitten) is running targeted phishing and malware operations against NGOs and individuals documenting protests: macro-laced Excel lures drop a C# backdoor (SloppyMIO) via AppDomainManager injection, the implant retrieves steganographic configuration from images hosted via GitHub/Google Drive and uses the Telegram Bot API for C2, supporting modules to run commands, exfiltrate files, deploy payloads, and persist via scheduled tasks; separate phishing infrastructure also harvests WhatsApp and Gmail credentials, and the campaign shows signs of LLM-assisted tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.