Monday, May 5, 2025
HomeCyber AttackDomestic Kitten - Extensive Surveillance Operation Against Iranian citizens

Domestic Kitten – Extensive Surveillance Operation Against Iranian citizens

Published on

SIEM as a Service

Follow Us on Google News

Researchers have studied and analyzed the workings of the hacking group Domestic Kitten. Domestic Kitten also goes by the name APT-50, and has been accused of deceiving people by having them install spyware on their mobile devices and PCs’.

The attacks were targeted against residents of 12 countries, including those of the UK, and USA. The installed spyware was being used to steal call recordings and media files from the victims’ devices.

Domestic Kitten was tricking people into downloading its spyware by:

- Advertisement - Google News
  1. repackaging an existing version of an authentic video game found on the Google Play store
  2. mimicking an app for a restaurant in Tehran
  3. providing a compromised app that publishes articles from a local news agency
  4. offering a fake mobile-security app
  5. supplying an infected wallpaper app containing pro-Islamic State imagery 
  6. masquerading as an Android application store to download further software
FurBall Repacked ‘Exotic Flowers’ cover, and an ISIS supported cover

It is believed that Domestic Kitten has been running this campaign at least for the past 4 years and that no less than 1200 individuals have been targeted and attacked.

CampaignStartEnd
hass44136Currently active
or4395243983
mat4380044013
hj4358643922
oth43252Currently active
hr4300943040
maj4300943617
mmh42917Currently active
msd42887Currently active
grt4288743709
Domestic Kitten Campaign list

The APT uses a mobile malware that is called FurBall. FurBall is transmitted via a variety of methods including phishing, Telegram channels, SMS messages containing a link to the malware, and Iranian websites.

Once FurBall is installed on the targeted device it intercepts SMS messages, grabs call logs, gathers device information, records communication, steals and stores media and files, monitors the device’s GPS coordinates, and many such activities.

Once the device has been compromised, it collates the data and is sent to command-and-control (C2) servers under Domestic Kitten’s usage since 2018.

Linked IP addresses were traced back to the Iranian cities of Tehran and Karaj. Another group that goes by the name of Infy too has been identified. This group targets users’ PCs’ and not their mobile devices. This group is believed to be state-sponsored and is in existence since 2007.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

Fox Kitten – Iranian Malware Campaign Exploiting Vulnerable VPN Servers To Hack The Organizations Internal Networks

Charming Kitten APT Hackers Group Abusing Google Services to Attack U.S Presidential Campaign Members

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Gunra Ransomware’s Double‑Extortion Playbook and Global Impact

Gunra Ransomware, has surfaced as a formidable threat in April 2025, targeting Windows systems...

Hackers Exploit 21 Apps to Take Full Control of E-Commerce Servers

Cybersecurity firm Sansec has uncovered a sophisticated supply chain attack that has compromised 21...

Hackers Target HR Departments With Fake Resumes to Spread More_eggs Malware

The financially motivated threat group Venom Spider, also tracked as TA4557, has shifted its...

RomCom RAT Targets UK Organizations Through Compromised Customer Feedback Portals

The Russian-based threat group RomCom, also known as Storm-0978, Tropical Scorpius, and Void Rabisu,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Exploit 21 Apps to Take Full Control of E-Commerce Servers

Cybersecurity firm Sansec has uncovered a sophisticated supply chain attack that has compromised 21...

Hackers Use Pahalgam Attack-Themed Decoys to Target Indian Government Officials

The Seqrite Labs APT team has uncovered a sophisticated cyber campaign by the Pakistan-linked...

NCSC Warns of Ransomware Attacks Targeting UK Organisations

National Cyber Security Centre (NCSC) has issued technical guidance following a series of cyber...