HOMETHREATSDomestic Kitten
APT / THREAT GROUP

Domestic Kitten

🇮🇷Iran-attributed
1
campaigns
3
aliases
Last seen:Mar 17, 2026

Intelligence Profile

An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along with surrounding voice recordings. Researchers with CheckPoint discovered the attack and named it Domestic Kitten. The targets are Kurdish and Turkish natives, and ISIS supporters, all Iranian citizens.

Threat Analysis

Domestic Kitten is a known-sophistication threat actor attributed to Iran, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

Domestic Kitten — Active Operations March 2026

Domestic Kitten is a unknown-motivation threat actor attributed to Iran. An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along with surrounding voice recordings. Researchers with CheckPoint discovered the attack and named it Domestic Kitten. The targ...

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Origin🇮🇷 Iran
Aliases3
SourceMalpedia

Also Known As

Bouncing GolfAPT-C-50Domestic Kitten

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.