← Back to all threat actors

Fox Kitten

Also known as UNC757, Parisite, Pioneer Kitten, RUBIDIUM, Lemon Sandstorm
Tracked as G0117

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: UNC757

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Parisite

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Pioneer Kitten

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: RUBIDIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Lemon Sandstorm

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0117

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Fox KittenCanonical Name
Lemon SandstormAlias
ParisiteAlias
Pioneer KittenAlias
RUBIDIUMAlias
UNC757Alias
G0117Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...