Tuesday, August 25, 2026

Operation Kitten: Hacktivist Groups Targeting Israel with Cyberattacks

A new platform known as the “kitten” project has emerged as a coordination hub for hacktivist campaigns targeting Israel, operating at the intersection of cyber activism and state-aligned influence.

While the operators publicly deny direct ties to Iran, technical evidence and infrastructure traces indicate a close relationship with an Iranian cybersecurity ecosystem and pro-Iranian hacktivist groups.

The “kitten” project functions as a semi‑private environment where select hacktivist actors can upload files, enter private chat rooms, and organize information operations.

For now, access and amplification appear limited to three main hacktivist groups: the well‑known “Handala Hacking Group” and the lesser‑known but operationally important “KilledByIsrael” and “CyberIsnaadFront”.

This is from “kitten”, a medium created for private conversations of these hacktivist groups.
This is from “kitten”, a medium created for private conversations of these hacktivist groups.

Together, these groups have been involved in doxing operations, the exposure of personal data of Israeli soldiers and civilians, and attempts to compromise industrial systems, including ICS and PLC environments.

Operation Kitten

Publicly, the operators behind “kitten” insist they are not based in Iran and downplay any direct Iranian affiliation, framing themselves instead as independent actors supporting offensive operations against Israel.

However, this narrative begins to unravel when the project’s early technical footprint is examined.

Before acquiring the public domain thekitten[.]group, a “demo” instance of the platform was hosted on a subdomain of the Iranian portal zagrosguard.ir, exposing a development path that runs through clearly Iranian infrastructure.

kitten domain.
kitten domain.

A legitimate Iranian IP address associated with this subdomain links the project to a broader Iranian cybersecurity network.

That network appears to be fronted by “Zagros”, a service that markets itself in Farsi as a domestic product enabling unrestricted access to “authorized or sensitive” systems via Iranian IP addresses.

According to its own description, Zagros is designed for programmers, gamers, students and professionals who need to access financial markets and other sensitive platforms without using foreign VPNs, ostensibly to reduce data leakage from services that require Iranian IP addresses.

Yet, despite presenting itself as a substantial commercial platform, Zagros shows no verifiable corporate registrations or typical indicators of a mature technology company.

Investigators describe it instead as a landing page crafted to impersonate a legitimate service while quietly enabling activity that “violates Iranian sanctions”.

Hacktivist Groups Involved

From this starting point, the hacktivist dimension becomes clearer: the same infrastructure that promises secure Iranian IP‑based access is also being used to incubate and deploy politically motivated cyber operations.

A closer review of the HTML code behind the early “kitten” instances confirms that the platform was fully pre‑developed within a Zagros subdomain before being migrated to its current domain.

Contact details embedded in the code lead to phone numbers later traced to a Turkish virtual operator, suggesting an effort to mask the actual location of the operators while maintaining regional proximity.

When one of the listed numbers was checked against Telegram, it resolved to a channel associated with the organization, reinforcing the link between the public front and the operational back end.

Additional traces show recruitment‑style postings in Farsi seeking programmers, security testers and related profiles, indicating that the organization is actively building technical capacity.

Admin panel.
Admin panel.

At the same time, an examination of an exposed backup of the “admin” panel, including .htaccess rules and an API‑driven backend, revealed a structured architecture for managing media, projects and content.

PHP scripts such as image.php, list.php and media.php handle controlled access to images and videos stored in directories tellingly named “pro_iran_projects”, further underscoring the ideological and geopolitical orientation of the platform.

Taken together, these elements portray the “kitten” project not as a spontaneous grassroots hacktivist space, but as a technically sophisticated, Iran‑linked infrastructure node.

It provides coordination, operational security and narrative amplification for hacktivist collectives engaged in sustained campaigns against Israeli targets, blurring the lines between patriotic hacking, deniable proxy activity and state‑aligned cyber operations.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands

ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large...

Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records

A multi-agent AI framework, utilizing Hermes and OpenClaw agents,...

Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud

A cluster of fraudulent websites impersonating Microsoft is using...

Multiple Zscaler Client Connector Flaws Enable Remote Code Execution

Zscaler has addressed several vulnerabilities in its Client Connector...

91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain

Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs)...

PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2

PavinLoader, a multi-stage .NET malware loader, operating across ClickFix,...

Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls

Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP)...

Related Articles

Recent News