Adversary

Remix Kitten

ORIGIN

Iran

Community Identifiers

Chafer, Cadelle, APT39, ITG07

Remix Kitten is an Iran-nexus adversary active since at least 2012, that CrowdStrike Intelligence assesses with high confidence operates in support of Iran’s Ministry of Intelligence and Security (MOIS).

The adversary conducts targeted intrusions in line with likely Iranian government counterintelligence priorities, with an emphasis on collecting data deemed valuable to enable other intelligence operations. Targeted organizations are consistently related to the travel and hospitality sectors, especially entities possessing significant amounts of personal information. It was the target of a series of leaks between 2018 and 2019 that publicized multiple sensitive elements of its operations.

Recent Activity

During the latter half of 2020, Remix Kitten has been identified as continuing to conduct activities against targets in the Middle East. These activities have aligned with the adversary's established tradecraft of favoring custom malware that requires a notable degree of operator interactivity, supplemented with lightly-customized open source tooling. In September 2020, the U.S. Department of the Treasury sanctioned Remix Kitten, its operational front company, and 45 individuals as carrying out targeted intrusion activities on behalf of the MOIS.

Targeted Nations

  • Flag Icon of the country Canada

    Canada

  • Flag Icon of the country Iran

    Iran

  • Flag Icon of the country Israel

    Israel

  • Flag Icon of the country Jordan

    Jordan

  • Flag Icon of the country Kuwait

    Kuwait

  • Flag Icon of the country Saudi Arabia

    Saudi Arabia

  • Flag Icon of the country Turkey

    Turkey

  • Flag Icon of the country United Arab Emirates

    United Arab Emirates

Artwork

Adversary: Remix Kitten - Threat Actor

Crowdstrike Remix Kitten

I have read and accept the terms and conditions

Download
Explore Next Adversary

Terms and conditions

In order to download the adversary artwork, we kindly request you to accept our terms and conditions displayed below.

This image (“artwork”), is the intellectual property of CrowdStrike, Inc. and its affiliates and licensors (collectively, “us” or “we”) and may include other marks, trademarks, copyrighted materials, and other intellectual property (“assets”) that belong t o us, including, without limitation, CrowdStrike, the CrowdStrike logo, and CrowdStrike Falcon. We retain all right, title and interest in and to the artwork and all assets included therein. This artwork is offered to you as a convenience for your lawful a nd non-commercial use, solely as authorized by us, and subject to your compliance with these terms and conditions (“terms”) and any other guidelines or specifications that we may provide from time to time. We reserve the right to change these terms at any time without prior notice.

You should periodically check the latest information posted herein to be sure that you are in compliance. By downloading the artwork, you attest that you are at least 18 years of age and agree to the following terms, which const itute the sole and entire agreement between you and us with respect to the artwork. We reserve all rights not expressly granted to you herein. You may not use or display the artwork in any way: (i) that violates the rights of any person or entity or that may give rise to civil or criminal liability under laws or regulations applicable to you, another user, and/or CrowdStrike; (ii) that is defamatory, obscene, indecent, abusive, harassing, violent, hateful, inflammatory or otherwise objectionable; (iii) tha t is false, deceptive, misleading or fraudulent, including but not limited to: (a) any attempt to impersonate any person or entity, including any other user, CrowdStrike or a CrowdStrike employee; (b) any attempt to misrepresent your identity or affiliation with any person or organization; or (iv) for the purposes of recruiting, advertising, solicitation or commercial activities of any kind without our express written consent.

THE ARTWORK IS PROVIDED TO YOU BY CROWDSTRIKE ON AN “AS IS” AND “AS AVAILABLE” BA SIS, WITHOUT ANY WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. EXCEPT TO THE EXTENT THAT A DISCLAIMER OF LIABILITY IS PROHIBITED UNDER APPLICABLE LAW, IN NO EVENT WILL CROWDSTRIKE, ITS AFFILIATES AND ITS LICENSORS, EMPLOYEES, AGENTS, OFFICERS AND DIRE CTORS BE LIABLE FOR DAMAGES OF ANY KIND, UNDER ANY LEGAL THEORY, ARISING OUT OF OR IN CONNECTION WITH YOUR USE, OR INABILITY TO USE, THE ARTWORK.