Home/Threat Actor/Pioneer Kitten
Threat Actor

Pioneer Kitten

pioneer_kitten_fox_kitten · iran · active since 2017

Pioneer Kitten (Fox Kitten / Parisite / Lemon Sandstorm / Rubidium / UNC757 / Br0k3r / G1042) is an Iran IRGC-aligned cyber cluster active since 2017 and formally attributed to Iran-based actors affiliated with the Islamic Revolutionary Guard Corps by joint US-government coordinated action on August 28, 2024 (joint Cybersecurity Advisory AA24-241A from FBI, CISA, and DoD Cyber Crime Center, paired with concurrent US Treasury OFAC sanctions against Iranian individuals Alireza Shafie Nasab and Reza Kazemifar Rahman plus Iranian front companies Najee Technology Hooshmand and Secnerd LLC, plus concurrent US DOJ indictments) , operationally distinguished from peer Iranian-state-aligned clusters by its dual operational model combining state-aligned cyber-espionage with explicit financial-motivation operations as an initial-access broker selling compromised network access to ALPHV/BlackCat, RansomHouse, NoEscape, and other ransomware affiliates against US schools, hospitals, municipal government, healthcare, financial-services, defense-industrial-base, and critical-infrastructure targets, defined operationally by opportunistic rapid-weaponization of newly-disclosed public- facing-VPN-and-network-security CVE exploits across a decade-spanning portfolio (CVE-2018-13379 Fortinet, CVE-2019-11510 Pulse Secure, CVE-2019-19781 Citrix, CVE-2020-5902 F5, CVE-2021-44228 Log4Shell, CVE-2022-1388 F5, CVE-2022-26134 Confluence, CVE-2022-47966 Zoho, CVE-2023-3519 Citrix, CVE-2024-3400 PAN-OS, CVE-2024-24919 Check Point, CVE-2024-21887 Ivanti) followed by ChunkyTuna/Pickled/Antak webshell deployment, Cobalt Strike Beacon hands-on-keyboard operations, and the Br0k3r/X_Proxy underground-forum persona-based access-sale tradecraft.

iran confidence: high 27 aliases MITRE ATT&CK G0117 ↗

Profile

Pioneer Kitten (also tracked as Fox Kitten, Parisite, Lemon Sandstorm, Rubidium, UNC757, Br0k3r, X_Proxy, and MITRE ATT&CK G1042) is an Iran IRGC-aligned cyber cluster active since at least 2017 and formally attributed to Iran-based actors affiliated with the Islamic Revolutionary Guard Corps by joint US-government coordinated action on August 28, 2024. The attribution event comprised joint Cybersecurity Advisory AA24-241A "Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations" (FBI, CISA, US Department of Defense Cyber Crime Center), concurrent US Department of the Treasury OFAC sanctions against two Iranian individuals (Alireza Shafie Nasab and Reza Kazemifar Rahman) and two Iranian front companies (Najee Technology Hooshmand and Secnerd LLC), and concurrent US Department of Justice indictments. The August 2024 attribution placed Pioneer Kitten among the formally-attributed Iranian state-aligned clusters alongside APT33 (IRGC), APT34 (MOIS), APT35 (IRGC-IO), APT39 (MOIS), and MuddyWater (MOIS), all already covered in this corpus. Pioneer Kitten is operationally distinguished from peer IRGC and MOIS clusters by its dual operational model combining state- aligned cyber-espionage with explicit financial-motivation operations as an initial-access broker (IAB) selling compromised network access to non-state ransomware affiliates including ALPHV/BlackCat, RansomHouse, NoEscape, and others. CrowdStrike's September 2020 "Who Is PIONEER KITTEN?" disclosure established this dual-motivation operational pattern in public reporting.

the pattern mirrors the APT41 / Earth Lusca / RedHotel / APT27 dual- motivation Chinese-cluster pattern (all already covered in this corpus) in a different national context and raises analytic questions about state sanction of cluster moonlighting versus separate funding streams. The downstream ransomware harm to US victims (schools, hospitals, municipal government, healthcare organizations, critical-infrastructure entities) produced substantial public-policy attention and was a central driver of the August 2024 coordinated US-government attribution-and- sanctions response. Operationally Pioneer Kitten is defined by its opportunistic tradecraft against public-facing vulnerabilities, the cluster has been among the most consistent and disciplined publicly- tracked clusters in rapidly weaponizing newly-disclosed CVEs against public-facing VPN, network-security, and remote-access infrastructure. The cluster's documented CVE-exploitation portfolio includes CVE-2018-13379 (Fortinet FortiOS), CVE-2019-11510 (Pulse Secure), CVE-2019-19781 (Citrix ADC / NetScaler), CVE-2020-5902 (F5 BIG-IP), CVE-2021-44228 (Log4Shell), CVE-2022-1388 (F5 BIG-IP), CVE-2022-26134 (Confluence), CVE-2022-47966 (Zoho ManageEngine), CVE-2023-3519 (Citrix ADC / NetScaler), CVE-2023-27532 (Veeam Backup & Replication), CVE-2023-46805 and CVE-2024-21887 (Ivanti Connect Secure), CVE-2024-3400 (PAN-OS), and CVE-2024-24919 (Check Point Quantum Security Gateway). The cluster does not appear to operate sustained zero-day-development capability and relies on rapid weaponization of disclosed n-day vulnerabilities, a tradecraft pattern that gave the cluster the original "Pioneer" name in CrowdStrike's framing (pioneering the use of newly-disclosed vulnerabilities at scale against accessible targets). Initial-access tradecraft is followed by deployment of ChunkyTuna, Pickled, Antak, JspSpy, and reGeorg web shells for persistent access, alongside Cobalt Strike Beacon for hands-on-keyboard operations, AdFind, BloodHound/SharpHound, and ngrok / FRP / Chisel for tunneling and persistent egress. Mimikatz and credential-theft tooling provide post-compromise privilege escalation. Rclone provides exfiltration capability. The ransomware-affiliate aspect of operations is enabled through the "Br0k3r" / "X_Proxy" underground-forum persona under which cluster operators sold compromised network access to ransomware affiliates. Targeting focus is overwhelmingly directed at US state and local government, schools (K-12 and higher education), hospitals and healthcare, financial services, defense industrial base, critical infrastructure (energy, water), and selected NGOs, alongside sustained operations against Israeli government, defense, and critical-infrastructure entities consistent with broader IRGC geopolitical priorities. The US-focused victim profile and the ransomware-enabling downstream harm differentiate Pioneer Kitten from peer IRGC clusters like APT35 (dissident-and-influence focus) and Imperial Kitten (Gulf-state IT supply-chain and US defense industrial base focus). A handful of operational notes: First, the cluster is operationally and attribution-wise distinct from MuddyWater (already covered as muddywater.yaml, MOIS-aligned, different operational model with no IAB / ransomware-enabling component). Some pre-2024 reporting conflated the two on the basis of overlapping Iranian-state attribution.

the cluster- level operational signatures remain distinguishable. Second, the August 2024 attribution at OFAC-designation tier (named individuals and front companies sanctioned) is substantially higher confidence than the vendor-research-consensus attribution tier that applies to Imperial Kitten (no formal OFAC or indictment action). Pioneer Kitten is one of the most formally-attributed Iranian state-aligned clusters as a result. Third, the cluster's continued operations despite the August 2024 attribution event illustrate (consistent with the Star Blizzard, Sandworm, and APT28 patterns in this corpus) that formal attribution and OFAC designations do not necessarily produce operational pauses for state-aligned clusters.

Aliases

27
pioneer kittenpioneer_kittenpioneerkittenfox kittenfox_kittenfoxkittenparisitelemon sandstormlemon_sandstormlemonsandstormrubidiumbr0k3rbr0k3rsbr0k3r_initial_access_brokerx_proxyx proxyunc757unc_757cobalt mirage overlapnajee technology hooshmandnajee_technology_hooshmandsecnerd llcsecnerd_llcshahid hemmatg1042atk 87atk87

Notable Campaigns

9
2024-2025Continued Operations Despite Attribution and Sanctions (2024-2025)
2024August 28, 2024 Joint Advisory AA24-241A + OFAC Sanctions (Najee Technology Hooshmand, Secnerd LLC)
2024DOJ Indictments of Iranian Front Company Operators (2024)
2022-2024Continued Israeli Targeting (2022-2024)
2021-2024Ransomware Affiliate Operations (2021-2024)
2020ClearSky Cyber Security: Fox Kitten Campaign (February 2020)
2020CISA / FBI: Iran-Based Threat Actor Exploits VPN Vulnerabilities (CISA AA20-259A, September 15, 2020)
2020CrowdStrike: Pioneer Kitten Naming and IAB Pattern Disclosure (2020)
2017-2020Pre-Disclosure Pioneer Kitten Activity (2017-2020)

Attribution & Reporting

Attributed by
US Federal Bureau of Investigation (FBI)US Cybersecurity and Infrastructure Security Agency (CISA)US Department of Defense Cyber Crime Center (DC3)US Department of the Treasury OFACUS Department of JusticeMicrosoftMicrosoft Threat Intelligence CenterCrowdStrikeMandiant / FireEyeDragosClearSky Cyber SecuritySentinelOnePRODAFTRecorded Future Insikt GroupSymantecCybereasonVolexityCluster25CyfirmaSekoia
Key reporting
reportClearSky Cyber Security: Fox Kitten Campaign, Widespread Iranian Espionage-Offensive Campaign (February 2020), seminal cluster disclosure
reportCrowdStrike: Who Is PIONEER KITTEN? (September 2020), IAB pattern disclosure
reportCISA / FBI Cybersecurity Advisory AA20-259A: Iran-Based Threat Actor Exploits VPN Vulnerabilities (September 15, 2020)
reportDragos: PARISITE Threat Profile
reportMandiant: UNC757 Iran-Based Ransomware Affiliate (multiple years)
reportMicrosoft: MERCURY Leveraging Log4j 2 Vulnerabilities in Unpatched Systems to Target Israeli Organizations (August 2022), adjacent reporting
reportFBI / CISA / DC3 Joint Cybersecurity Advisory AA24-241A: Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations (August 28, 2024), seminal formal attribution
reportUS Department of Treasury OFAC: Sanctions Against Najee Technology Hooshmand, Secnerd LLC, Alireza Shafie Nasab, and Reza Kazemifar Rahman (August 28, 2024)
reportUS DOJ Indictments: Iranian Nationals Charged in Multi-Year Hacking Campaign (August 2024)
reportSentinelOne Labs: Iran-Based Pioneer Kitten Tracking
reportSekoia: Pioneer Kitten / Fox Kitten Tracking (2024)
reportRecorded Future Insikt Group: Pioneer Kitten Iran IAB Tracking
reportCluster25: Pioneer Kitten Iran Initial-Access-Broker Operational Profile
reportCyfirma: Pioneer Kitten Iran Tracking (multiple years)
reportMalpedia Actor Profile: Pioneer Kitten
reportMITRE ATT&CK Group G1042, Pioneer Kitten

Operational

State sponsor

Iran, Islamic Revolutionary Guard Corps (IRGC). Attribution to IRGC at high-confidence formal-government tier is grounded in the August 28, 2024 coordinated US government action: joint Cybersecurity Advisory AA24-241A "Iran-Based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations" (FBI, CISA, US Department of Defense Cyber Crime Center) explicitly attributed Pioneer Kitten operations to "Iran-based cyber actors" affiliated with the IRGC, paired with concurrent US Department of the Treasury OFAC designations sanctioning two Iranian individuals (Alireza Shafie Nasab and Reza Kazemifar Rahman) and two Iranian front companies (Najee Technology Hooshmand and Secnerd LLC) for their roles in Pioneer Kitten ransomware-enabling operations.

The August 2024 attribution placed Pioneer Kitten among the formally-attributed Iranian state-aligned clusters alongside APT33 (IRGC), APT34 (MOIS), APT35 (IRGC-IO), APT39 (MOIS), and MuddyWater (MOIS), all already covered in this corpus. The cluster is operationally distinguished from peer IRGC clusters by its dual operational model combining state-aligned cyber- espionage with explicit financial-motivation operations as an initial-access broker (IAB) selling network access to non-state ransomware affiliates including ALPHV/BlackCat, RansomHouse, and NoEscape. The dual-motivation pattern mirrors the APT41 / Earth Lusca / RedHotel / APT27 dual-motivation Chinese-cluster pattern and raises analytic questions about state sanction of cluster moonlighting versus separate funding streams.

Motivations
espionage, intelligence_gathering, initial_access_brokering, ransomware_enabling, financial_gain, critical_infrastructure_targeting, opportunistic_exploitation, hack_and_leak_operations
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASHARPHOUNDSMBEXEC
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin