Skip to content
← All Threat Actors
Nation-State high Iran

Pioneer Kitten / Fox Kitten

Iranian state-sponsored (IRGC-aligned) with dual criminal access-brokering mandate · State espionage / intelligence collection and criminal access brokering for ransomware operators

Reports 1
Active Since 2017
Last Reported 29 Jun 2026
Sectors Targeted healthcare, finance, critical-infrastructure, transport

Tactics, Techniques & Procedures (TTPs)

  • Systematic VPN appliance exploitation within days of CVE disclosure (Citrix ADC, F5 BIG-IP, Ivanti Connect Secure, Palo Alto PAN-OS)
  • Web shell deployment (COWTOWER) for persistent server-side access independent of subsequent patching
  • PLINK SSH tunnels for encrypted internal network traversal post-compromise
  • Active Directory enumeration and credential dumping for deep network access establishment
  • Access brokering under "Br0k3r" dark web persona: sells verified corporate footholds to ransomware affiliates (NoEscape, ALPHV/BlackCat, RansomHub confirmed)
  • Rogue VPN account creation for long-term persistent access (dwell times of 6+ months documented)
  • Dual-track operations: intelligence collection against strategic targets running in parallel with commercial access sales

Known Targets

US federal agencies and defence contractorsIsraeli government and military organisationsHealthcare and research institutions (US, Australia, UK, Europe)Technology companies with high-value network accessOrganisations with VPN-exposed perimeters globally

Analyst Notes

The dual mandate — state espionage for the IRGC alongside criminal access brokering for ransomware operators — makes Pioneer Kitten operationally distinct from most nation-state actors. Despite CISA/FBI public attribution in August 2024 (Advisory AA24-241A), operations continued unabated. Ransomware partners confirmed: NoEscape, ALPHV/BlackCat, and RansomHub affiliates — meaning Pioneer Kitten initial access underlies a portion of high-impact RaaS attacks on US critical infrastructure. CVE weaponisation typically occurs within 48 hours of public disclosure.

Also Known As

Fox Kitten (CrowdStrike)Lemon Sandstorm (Microsoft)UNC757 (Mandiant)RubidiumPARISITEParasite