Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0117
MITRE ATT&CK Group

Fox Kitten (G0117)

UNC757ParisitePioneer KittenRUBIDIUMLemon Sandstorm
ShareXLinkedInRedditHN

[Fox Kitten](https://attack.mitre.org/groups/G0117) is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. [Fox Kitten](https://attack.mitre.org/groups/G0117) has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.(Citation: ClearkSky Fox Kitten February 2020)(Citation: CrowdStrike PIONEER KITTEN August 2020)(Citation: Dragos PARISITE )(Citation: ClearSky Pay2Kitten December 2020)

▪Techniques used (41)

T1105Ingress Tool TransferT1059Command and Scripting InterpreterT1530Data from Cloud StorageT1018Remote System DiscoveryT1110Brute ForceT1210Exploitation of Remote ServicesT1136.001Local AccountT1560.001Archive via UtilityT1027.010Command ObfuscationT1005Data from Local SystemT1585Establish AccountsT1021.005VNCT1552.001Credentials In FilesT1217Browser Information DiscoveryT1059.003Windows Command ShellT1027.013Encrypted/Encoded FileT1213.005Messaging ApplicationsT1021.002SMB/Windows Admin SharesT1190Exploit Public-Facing ApplicationT1555.005Password ManagersT1003.003NTDST1087.001Local AccountT1087.002Domain AccountT1021.004SSHT1505.003Web ShellT1053.005Scheduled TaskT1036.004Masquerade Task or ServiceT1003.001LSASS MemoryT1090ProxyT1012Query RegistryT1572Protocol TunnelingT1021.001Remote Desktop ProtocolT1102Web ServiceT1039Data from Network Shared DriveT1078Valid AccountsT1046Network Service DiscoveryT1546.008Accessibility FeaturesT1585.001Social Media AccountsT1036.005Match Legitimate Resource Name or LocationT1059.001PowerShellT1083File and Directory Discovery

▪Software used (5)

S0020China ChoppermalwareS0556Pay2KeymalwareS0508ngroktoolS0029PsExectoolS9001SystemBCmalware
G0117on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.