Pioneer Kitten
Iranian state-affiliated intrusion set publicly attributed by FBI, CISA, and DC3 in joint advisory AA24-241A as connected to the Government of Iran and operating partly through an Iranian IT-services front company. Operates as an initial-access broker: weaponizes edge-device n-days (Citrix NetScaler, F5 BIG-IP, Pulse Connect Secure, Check Point Security Gateways) to obtain footholds at U.S., Israeli, and UAE targets, then sells access to or collaborates with ransomware affiliates including ALPHV/BlackCat and NoEscape to deploy ransomware downstream.
Aliases
Motivations
Target sectors
Target countries
Lineage & relationships
full graph →Diamond Model
Caltagirone / Pendergast / Betz 2013 — four-vertex attribution framework.
MITRE ATT&CK techniques
Timeline
1 eventIndicators of compromise
4 indicators| Type | Value | First seen | Source |
|---|---|---|---|
| Domain | Pioneer Kitten infrastructure domain listed in CISA AA24-241A Table 10 (Indicators of Compromise - Recent). First observed February 2024 and still active through August 2024 per the joint FBI/CISA/DC3 advisory. | Jan 31, 2024 | CISA |
| IPv4 | DigitalOcean-hosted IP observed by FBI in Pioneer Kitten operations January-August 2024, listed in Table 10 of CISA AA24-241A. The group exploits edge devices (Citrix Netscaler CVE-2019-19781/CVE-2023-3519, F5 BIG-IP CVE-2022-1388, Ivanti CVE-2024-21887, PanOS CVE-2024-3400, Check Point CVE-2024-24919) for initial access. | Dec 31, 2023 | CISA |
| Name | Credential-capturing webshell artifact dropped by Pioneer Kitten on compromised Citrix Netscaler appliances - the file collects login credentials and is placed in the same directory as a PHP webshell (ctxHeaderLogon.php / netscaler.php) per CISA AA24-241A. | Sep 30, 2023 | CISA |
| Domain | Recent infrastructure domain listed in Table 10 of CISA AA24-241A (FBI/CISA/DC3 joint advisory, 28 Aug 2024) on Iran-based Pioneer Kitten / Fox Kitten / UNC757 / Parisite / Lemon Sandstorm / Br0k3r enabling ransomware affiliates NoEscape, RansomHouse and ALPHV/BlackCat. First observed September 2022, most recently August 2024. | Aug 31, 2022 | CISA |
Related actors
shared ATT&CK techniques- KP · DPRKAndariel3 shared techniques
- ?? · UnknownPlay3 shared techniques
- RU · Russia8Base2 shared techniques
- ?? · UnknownAkira2 shared techniques
- ?? · UnknownALPHV/BlackCat2 shared techniques
- RU · RussiaAPT282 shared techniques
References
cite this page
Threat Intel Tracker. (2026-05-19). Pioneer Kitten — actor profile. Retrieved from https://threatintel.local/actors/pioneer-kitten