Skip to content
Deep Dive high HealthcareFinanceCritical InfrastructureTransport

Pioneer Kitten: How Iran's IRGC Became an Access Broker for Ransomware Gangs

Executive Summary

Pioneer Kitten is an Iranian state-sponsored threat actor assessed to operate in direct alignment with the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2017, the group has conducted intrusion campaigns against US, European, Middle Eastern, and Australian organisations at scale — targeting network perimeter devices including VPN appliances and firewalls as the primary point of entry.

What distinguishes Pioneer Kitten from other state-sponsored groups is its commercial layer. The FBI assesses that a significant share of the group’s operations are designed not for espionage but for access brokering: establishing persistent network footholds in victim organisations and then selling that access to criminal ransomware affiliates, including NoEscape, ALPHV/BlackCat, and RansomHub. In doing so, Pioneer Kitten sits at the intersection of nation-state intelligence gathering and financially motivated ransomware, collecting geopolitical intelligence while simultaneously generating revenue from access sales that result in disruptive ransomware deployments against US and European targets.

The group was formally attributed in a joint Cybersecurity Advisory issued by the FBI, CISA, and the Department of Defense Cyber Crime Center (DC3) on August 28, 2024. Since then, intrusion activity attributed to Pioneer Kitten has continued, with sector targeting consistent with both IRGC intelligence priorities and ransomware affiliate demand.

Threat Actor Profile

Pioneer Kitten is tracked under multiple names across the vendor community:

  • Pioneer Kitten (FBI, public sector usage)
  • Fox Kitten (CrowdStrike)
  • Lemon Sandstorm / formerly Rubidium and Parisite (Microsoft)
  • UNC757 (Mandiant/Google Threat Intelligence)
  • Br0k3r (dark web persona used in access broker activity)

The group is assessed to operate in support of IRGC objectives, with a likely composition spanning both intelligence officers and contracted Iranian hackers. The dual mandate — state espionage and ransomware facilitation — appears deliberate. Iran’s strategic doctrine increasingly views financially motivated cybercriminal activity as a tool of plausible deniability and a method for draining adversary resources while maintaining distance from attribution.

Pioneer Kitten has operated continuously since 2017, showing sustained capability and operational patience. The group does not frequently abandon infrastructure when discovered; rather, it pivots to alternative access routes within the same victim network when one path is cut off. Dwell times of six months to over a year have been observed in confirmed intrusions.

TTPs and Tradecraft

Initial Access: Perimeter Exploitation at Scale

Pioneer Kitten’s defining characteristic is systematic exploitation of internet-facing network infrastructure. The group conducts broad scanning of IP address ranges to identify vulnerable VPN concentrators, firewalls, and remote access appliances, then targets unpatched instances at scale. The attack chain typically begins within days of a CVE being made public — sometimes within 24 hours for high-value vulnerabilities.

Key vulnerabilities historically exploited:

CVEProductTypeNotes
CVE-2019-19781Citrix ADC/GatewayRCEEarly signature technique
CVE-2022-1388F5 BIG-IPAuth bypass/RCEExploited heavily in 2022-2023
CVE-2023-3519Citrix NetScalerUnauthenticated RCEActive exploitation confirmed
CVE-2024-21887Ivanti Connect SecureRCE (combined with CVE-2023-46805)2024 campaign
CVE-2024-3400Palo Alto PAN-OS GlobalProtectUnauthenticated RCEExploited within days of disclosure
CVE-2024-24919Check Point VPNInfo disclosure / credential accessActive exploitation in 2024

The pattern is consistent: the group maintains a near-exhaustive target list of organisations using specific VPN or remote access products, and upon identification of a new exploitable CVE, moves rapidly through that list before patches are applied.

Establishing Persistence

Once inside a perimeter device, Pioneer Kitten’s priorities are credential extraction and persistence establishment. Common post-exploitation activity includes:

  • Credential dumping from the compromised appliance, including VPN user credentials and LDAP integration secrets
  • Deploying web shells to maintain access independent of the initial vulnerability being patched
  • PLINK tunneling: using the PuTTY link tool to create encrypted tunnels that allow inbound connections without requiring further exploitation
  • Enumerating Active Directory using legitimate admin tools to understand network topology, identify high-value targets, and locate domain controller credentials
  • Creating rogue VPN accounts using harvested credentials to maintain access even if the original exploit path is closed

The group is known for patient, methodical reconnaissance following initial access. Rather than immediately deploying ransomware or exfiltrating data, Pioneer Kitten operators spend time mapping the network, identifying crown jewel assets, and establishing multiple redundant persistence mechanisms before the next phase of operations.

Dual-Track Operations

Following access establishment, Pioneer Kitten’s operations diverge into two tracks depending on the victim’s intelligence value and the current tasking from IRGC handlers:

Track 1: Intelligence Collection For victims of strategic interest — government contractors, defence primes, healthcare research, financial intelligence — the group maintains persistent, low-noise access and performs data exfiltration over extended periods. The IRGC’s intelligence objectives include technology transfer targets, sanctions evasion intelligence, and political intelligence on adversary government and military organisations.

Track 2: Access Sale For victims that represent ransomware revenue opportunity — large enterprises with demonstrable ability to pay ransoms — the group sells access packages through dark web forums and direct outreach to ransomware affiliate operators. The Br0k3r persona is the primary identity used for these transactions. Access packages include network credentials, internal topology maps, and assessed ransomware deployment feasibility.

Confirmed ransomware partners using Pioneer Kitten access include:

  • NoEscape (now defunct, formerly operated before exit scam in late 2023)
  • ALPHV/BlackCat (disrupted by FBI December 2023, with former affiliates now distributed across other groups)
  • RansomHub (currently one of the most active RaaS operations; Pioneer Kitten continues to supply access)

Targeting and Victim Sectors

Pioneer Kitten’s victim profile reflects its dual mandate. The group does not restrict targeting to sectors with immediate intelligence value — any internet-exposed perimeter device using a vulnerable product is a candidate for initial access. The question of what happens next depends on assessment of the victim’s value profile.

Primary targeted sectors:

  • Healthcare: US hospitals and health systems represent both intelligence targets (medical research, pharmaceutical IP) and ransomware revenue targets with high pressure to restore systems quickly
  • Financial services: Banks, investment managers, and fintech companies targeted for both financial intelligence and ransomware capability
  • Government and defence: Federal agencies and defence contractors targeted for intelligence collection; access sometimes sold to ransomware operators when espionage yield is limited
  • Critical infrastructure: Energy, utilities, and transport; primarily intelligence focused but access sale to ransomware operators has been documented
  • Education: Universities targeted for research data, particularly in medical, defence, and emerging technology disciplines

Geographic focus:

  • United States (primary)
  • Israel (consistent with IRGC regional priorities)
  • United Arab Emirates
  • Australia
  • United Kingdom and broader EU

Iran’s adversarial relationship with the US and Israel provides significant intelligence motivation. The UK and Australia are targeted in part due to Five Eyes intelligence-sharing relationships and as proxies for US-aligned policy positions.

Historical Incidents and Impact

2020-2021 — Initial Perimeter Exploitation Wave Pioneer Kitten’s first documented campaigns exploited Citrix ADC vulnerabilities at scale across US government and private sector networks. The group demonstrated ability to hold persistent access in multiple large enterprises simultaneously, with some intrusions going undetected for over 12 months.

2022-2023 — F5 and Citrix Campaign Expansion Exploitation of F5 BIG-IP CVE-2022-1388 and Citrix CVE-2023-3519 enabled the group to broaden its victim set significantly. The emergence of the NoEscape and ALPHV/BlackCat ransomware partnerships in this period suggests Pioneer Kitten had already developed relationships with criminal operators by 2022, coinciding with an uptick in ransomware deployments following long-dwell intrusions.

2024 — Ivanti, PAN-OS, and the CISA Advisory The Ivanti Connect Secure mass exploitation in early 2024, which Pioneer Kitten participated in alongside multiple other threat actors, was followed by exploitation of the PAN-OS GlobalProtect zero-day (CVE-2024-3400) and Check Point VPN (CVE-2024-24919) within months. The CISA/FBI/DC3 joint advisory in August 2024 represented the US government’s formal public attribution, identifying the group and its ransomware brokering activity explicitly.

2025-2026 — RansomHub Partnership and Continued Activity Despite the public advisory, Pioneer Kitten operations have continued with no material reduction in tempo. The group’s pivot to RansomHub following the disruption of ALPHV/BlackCat demonstrates adaptability — the ransomware relationships survive disruption of individual operators because the access brokering model is fundamentally a marketplace, not a bilateral partnership.

The elevation of Iranian cyber activity observed following US military actions in the broader Middle East in 2025-2026 has been accompanied by increased Pioneer Kitten scanning frequency and attempted exploitation of newly disclosed edge device vulnerabilities within the first 48 hours of CVE publication.

Defensive Implications

Patch perimeter devices as a tier-one priority. The central message from seven years of Pioneer Kitten activity is that unpatched internet-facing VPN appliances and firewalls are the primary entry point. Patching edge devices must be treated with the same urgency applied to domain controller vulnerabilities — they are in practice equivalent in terms of access risk.

Implement asset discovery for all internet-facing services. Organisations frequently do not know the complete inventory of perimeter devices exposed to the internet, particularly in complex enterprise environments with acquired entities. Attack surface management tooling should provide continuous visibility into externally accessible services.

Monitor for PLINK tunneling and unexpected outbound connections from network appliances. Network appliances should not be initiating outbound PLINK connections. Any outbound SSH from a firewall or VPN concentrator to an unknown external IP should be treated as a compromise indicator and investigated immediately.

Audit VPN accounts and access logs immediately following any perimeter device CVE publication. Pioneer Kitten moves within days. The response window between CVE publication and exploitation attempt is measured in hours to days, not weeks. Account audits, log reviews, and configuration checks should begin immediately upon disclosure, not after patch deployment.

Threat-hunt for LDAP and AD enumeration from appliance context. Post-exploitation enumeration of Active Directory from the context of a compromised VPN or firewall is a behavioural signature. Security monitoring should flag unusual LDAP queries or AD enumeration originating from network device IP addresses.

Treat long-dwell intrusions as the baseline assumption. If Pioneer Kitten access is confirmed, assume the intruder has been present for months, has multiple persistence mechanisms, and has had time for extensive network mapping. Incident response scope should be planned accordingly, including re-issuance of credentials, review of all privileged access logs for the assumed dwell period, and forensic investigation of all systems with administrative access.

Consider supply chain risk if selling network access to ransomware affiliates. The RansomHub partnership means that a Pioneer Kitten compromise may not result in any observable activity for extended periods before ransomware is deployed by a separate criminal actor with different tooling. IR teams should be prepared for the gap between initial access and ransomware deployment to span weeks to months, with the entity deploying ransomware being operationally distinct from the entity that established access.