Researchers have studied and analyzed the workings of the hacking group Domestic Kitten. Domestic Kitten also goes by the name APT-50, and has been accused of deceiving people by having them install spyware on their mobile devices and PCs’.
The attacks were targeted against residents of 12 countries, including those of the UK, and USA. The installed spyware was being used to steal call recordings and media files from the victims’ devices.
Domestic Kitten was tricking people into downloading its spyware by:
It is believed that Domestic Kitten has been running this campaign at least for the past 4 years and that no less than 1200 individuals have been targeted and attacked.
Campaign | Start | End |
hass | 44136 | Currently active |
or | 43952 | 43983 |
mat | 43800 | 44013 |
hj | 43586 | 43922 |
oth | 43252 | Currently active |
hr | 43009 | 43040 |
maj | 43009 | 43617 |
mmh | 42917 | Currently active |
msd | 42887 | Currently active |
grt | 42887 | 43709 |
The APT uses a mobile malware that is called FurBall. FurBall is transmitted via a variety of methods including phishing, Telegram channels, SMS messages containing a link to the malware, and Iranian websites.
Once FurBall is installed on the targeted device it intercepts SMS messages, grabs call logs, gathers device information, records communication, steals and stores media and files, monitors the device’s GPS coordinates, and many such activities.
Once the device has been compromised, it collates the data and is sent to command-and-control (C2) servers under Domestic Kitten’s usage since 2018.
Linked IP addresses were traced back to the Iranian cities of Tehran and Karaj. Another group that goes by the name of Infy too has been identified. This group targets users’ PCs’ and not their mobile devices. This group is believed to be state-sponsored and is in existence since 2007.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Also Read
A high-severity vulnerability has been discovered in the popular web framework, Next.js, which allows attackers…
In a decisive move to bolster cloud security, the Cybersecurity and Infrastructure Security Agency (CISA)…
Fortinet, a global leader in cybersecurity solutions, has issued an urgent security advisory addressing two…
Google has released a new security update on the Stable channel, bringing Chrome to version 131.0.6778.204/.205…
The Cybersecurity and Infrastructure Security Agency (CISA) has released new best practice guidance to safeguard…
The VIPKeyLogger infostealer, exhibiting similarities to the Snake Keylogger, is actively circulating through phishing campaigns. …