Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
8
techniques
4
software
8,916
corpus matches
profile
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.
techniques
8 attributed · most-instrumented first
software
4 malware & tools attributed
Cobalt Strike
S0154
TDTESS
S0164
Matryoshka
S0167
Empire
S0363
read this carefully
8,916 corpus matches is not attribution
That count is indicators which exhibit techniques CopyKittens is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
showing 30 of 8,916