Uptime Hamster: 10d 8h 50mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza CopyKittens

CopyKittens

1 incidentes 1 paises 0 sectores apt IR Ultimo: 2026-05-25
Aliases: G0052, Slayer Kitten, APT COPYKITTENS, DarkHydrus, incluyendo actividades relacionadas con espionaje, brechas de seguridad
Ver en IntelTracker → APTTrail →
CopyKittens, also known by the aliases G0052, Slayer Kitten, and Rocket Kittens, is an Iranian state-sponsored cyber espionage group that commenced operations in 2013. The group's primary motivation is information theft and espionage, focusing on strategic targets in the Middle East, Europe, and North America. They gained notoriety for the extensive 'Operation Wilted Tulip' campaign, which involved sophisticated multi-stage attacks. A distinguishing characteristic of CopyKittens is their persistent operational methodology, often leveraging a combination of custom-developed malware and commercially available penetration testing tools.

Aliases del actor

G0052Slayer KittenAPT COPYKITTENSDarkHydrusincluyendo actividades relacionadas con espionajebrechas de seguridad

Actores similares

apt-copykittensactor · 1apt-darkhydrusactor · 1apt-desertfalconactor · 1apt-rampantkittenactor · 1apt-stealthfalconactor · 1Fox Kittenapt · 1BANISHED KITTENapt · 0Magic Kittenapt · 0Flash Kittenapt · 0Ferocious Kittenapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknowns3-eu-west-1.amazonaws.comAPT COPYKITTENS indicators and references
Repositoriounknowngithub.comAPT COPYKITTENS indicators and references
Webunknownraw.githubusercontent.comAPT COPYKITTENS indicators and references
Motivacion