Imperial Kitten
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Imperial Kitten, also known as Tortoiseshell and TA456, is an Iranian nation‑state hacker group that has been active since at least July 2018 and is publicly attributed to Iran by multiple security researchers. The group operates under the direction of the Iranian state and has been observed conducting cyber operations that align with Tehran’s strategic interests, particularly in the context of the ongoing cyber confrontation with Israel.
Imperial Kitten’s targeting has focused on Israeli maritime and logistics firms, as well as broader sectors such as healthcare, government, and energy organizations within Israel, often using watering hole techniques to compromise websites frequented by employees of those entities. The group has also directed supply chain attacks against information technology providers in Saudi Arabia, employing both custom and off‑the‑shelf malware with the goal of compromising the providers’ downstream customers. Public reporting notes that some of the group’s operations aim to exfiltrate user data, others seek to disrupt or destroy systems, and a subset is intended to spread disinformation, reflecting the broader objectives of Iranian cyber activity amid regional tensions.
The group’s tactics, techniques and procedures include compromising legitimate websites to host malicious JavaScript that harvests visitors’ IP addresses, screen resolutions, previously visited URLs and language preferences, thereby enabling future targeting. Imperial Kitten has registered domains that impersonate legitimate JavaScript libraries—such as jquery‑stack[.]online—to lure victims into executing malicious code. It has repeatedly abused the uPress hosting service, which was also leveraged by the Iranian group Emennet Pasargad in 2020 to deface thousands of Israeli sites. In addition, the actor has demonstrated the ability to rapidly exploit newly disclosed vulnerabilities, using tailored tools to gain initial access, a capability noted by Microsoft as indicative of an evolving Iranian cyber posture.
Notable operations attributed to Imperial Kitten include a watering hole campaign that targeted at least eight Israeli websites—including SNY Cargo, Depolog and SZM—using malicious scripts to collect visitor data, and a separate campaign in which a suspected Iranian threat actor tracked by Mandiant as UNC3890 employed similar watering hole methods against shipping, healthcare, government and energy targets in Israel. The group’s use of the jquery‑stack[.]online domain, which mimics the legitimate jQuery framework, has been observed in multiple incidents, including a earlier 2017 Iranian campaign that also relied on domain impersonation. These activities illustrate a pattern of leveraging trusted web resources, supply chain relationships and rapid vulnerability exploitation to advance Iranian intelligence and disruption goals.
Incidents
Attributed incidents are available to members.
0 incidents