Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
1 malware family

RedKitten

Also known asredkitten

RedKitten is an Iran-linked, Farsi-speaking threat actor or campaign aligned with Iranian state interests, first observed in January 2026 and reported as active since late 2025. It has conducted targeted cyber-espionage operations against Iranian civil society, including human rights NGOs, activists, and other individuals documenting human rights abuses and protest crackdowns in Iran. Reported victim categories also include academics, journalists, government officials, business leaders, and members of the Kurdish community. Multiple reports state the activity targeted Iranian interests and that at least 50 individuals were directly impacted. RedKitten is associated with a custom backdoor/implant called SloppyMIO. Reported delivery commonly used Farsi-named 7-Zip archives containing macro-enabled Microsoft Excel lures themed around lists of protesters killed in Tehran between late December 2025 and January 2026. Enabling the malicious VBA macro triggered AppDomainManager injection to load a dropped C# DLL, AppVStreamingUX_Multi_User.dll, from %LOCALAPPDATA%\Microsoft\CLR_v4.0_32\NativeImages, leading to execution of SloppyMIO. HarfangLab reported indicators that the VBA macro may have been generated or obfuscated with large language models, and other reporting described the campaign as incorporating AI or LLM-assisted development into the attack lifecycle. SloppyMIO is described as modular and capable of retrieving and caching modules, arbitrary command execution, file collection and exfiltration, writing files to disk, launching arbitrary processes, and further malware distribution. Persistence was reported via scheduled tasks executed every two hours. For command-and-control and staging, RedKitten used GitHub as a dead-drop resolver, Google Drive for configuration and payload/module retrieval including steganographically embedded configuration data, and Telegram or the Telegram Bot API for command-and-control and exfiltration. Use of GitHub, Google Drive, and Telegram was specifically noted as commoditized infrastructure that complicates infrastructure-based tracking while creating OPSEC exposure. The campaign also operated credential-harvesting phishing infrastructure, including a WhatsApp-themed site at whatsapp-meeting.duckdns[.]org and a Gmail-themed phishing page. The WhatsApp lure mimicked WhatsApp Web, captured credentials, and requested camera, microphone, and geolocation access; the Gmail lure harvested email credentials and two-factor authentication codes. Reporting notes TTP overlap with Iranian threat activity, including MuddyWater’s Operation Olalampo and similarities to Tortoiseshell, Nemesis Kitten, and Charming Kitten. HarfangLab assessed the actor as aligned with Iranian government security interests, but the content does not provide a more specific formal attribution to a named state organization. Known alias in the provided content: redkitten.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics13 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1204
User Execution
T1204.002
Malicious File
TA0005
Stealth
2 techniques
T1027
Obfuscated Files or Information
T1027.003
Steganography
T1140
Deobfuscate/Decode Files or Information
TA0011
Command and Control
2 techniques
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1102
Web Service
T1102.001
Dead Drop Resolver
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
IOCS

Observables

3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables3

Domains, IPs, and hashes tied to this actor, refreshed continuously.