Recommended Free Tools
Kaspersky’s June 2021 report described a Windows surveillance operation it called Ferocious Kitten, which it assessed had targeted Persian-speaking people apparently based in Iran since at least 2015. Its analyzed malware, MarkiRAT, could capture keystrokes, clipboard contents and screenshots, transfer files, and run commands. The report also found clues suggesting Android targeting, but Kaspersky did not obtain Android samples to analyze. Its findings did not establish that an Iranian government agency directed the operation.
What was Ferocious Kitten?
Ferocious Kitten is the name Kaspersky’s Global Research and Analysis Team (GReAT) used for a set of cyber-surveillance activity described in its report “Ferocious Kitten: 6 years of covert surveillance in Iran,” published 16 June 2021. Kaspersky said the activity had targeted Persian-speaking individuals who appeared to be in Iran since at least 2015.
The report’s central technical finding concerned Windows malware named MarkiRAT. Kaspersky analyzed Windows samples and described capabilities that could let an operator monitor activity and interact with an infected computer. The report did not establish how many people were targeted or compromised.
How did the Windows malware reach victims?
Malicious documents and earlier executable files
Two suspicious documents uploaded to VirusTotal in July 2020 and March 2021 brought the activity to Kaspersky’s attention. The documents used malicious macros to drop executable files and showed political decoy material. Kaspersky also found older executable samples dating back to at least 2015. That suggests direct executable delivery predated the more recently observed weaponized documents; it does not identify every delivery route or establish when the operation began.
#1 Best Overall
What MarkiRAT could do
Kaspersky reported that MarkiRAT could log keystrokes and clipboard contents, upload and download files, execute commands, and capture screenshots. These are surveillance and remote-control capabilities, rather than evidence that every victim experienced every form of monitoring.
How did Ferocious Kitten target Telegram and Chrome?
Kaspersky analyzed variants that changed how Telegram Desktop and Google Chrome launched, allowing the malicious component to run alongside the legitimate application. As a result, a person could start a familiar program while the implant also ran. This launch behavior is more specific than simply targeting users of Telegram: it describes how certain analyzed variants were configured to accompany the applications.
The report also cited targeting of Telegram as one of several clues behind its assessment of the operation’s intended audience. It did not establish that all Telegram users, or all users of the affected applications, were at risk.
Why did Kaspersky assess that the victims were mainly in Iran?
Kaspersky’s assessment rested on several indicators considered together, not on a confirmed identity for every victim. The report said that “The attack appears to be mainly targeting Iranian victims.” It pointed to:
Rank #3
- Mostly Persian-language filenames and a MarkiRAT check for the Persian keyboard-language identifier.
- Malicious subdomains impersonating Iranian services.
- A backdoored version of Psiphon, an open-source VPN used to bypass censorship.
- Targeting of Telegram.
- Political decoy images or videos.
These details support Kaspersky’s target assessment, but do not prove that every victim was Iranian or establish who sponsored or directed the activity.
Did Kaspersky confirm Android spyware?
No. Kaspersky found URLs on command infrastructure that referred to Android applications or components, including APK and DEX files. It did not obtain the underlying Android samples, so it could not reverse-engineer them to confirm their purpose. The report therefore suggests Android targeting; it does not confirm an Android implant’s capabilities or establish which devices were affected.
Was Ferocious Kitten connected to Domestic Kitten or Rampant Kitten?
Kaspersky compared Ferocious Kitten with Domestic Kitten and Rampant Kitten, noting similarities or reminiscent patterns in victim profiles and tactics. These included patterns in command-and-control URLs and efforts to collect password-manager data. But the report said it found no solid connections between the groups’ codebases or infrastructure.
Rank #4
Possible explanations, such as shared developers or a mutual supervisor, were speculation in the report, not established attribution. The similarities do not show that the groups were one organization or prove that an Iranian state agency directed Ferocious Kitten.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11What the report’s timeline does—and does not—show
| Date | What Kaspersky reported | What it establishes |
|---|---|---|
| At least 2015 | Older MarkiRAT executables date back to this year. | A minimum observed activity date, not a precise start date. |
| July 2020 and March 2021 | Two suspicious documents were uploaded to VirusTotal. | When those documents were uploaded, not necessarily when they were created or used against victims. |
| 16 June 2021 | Kaspersky published its Securelist report. | The publication date of the findings described here. |
These are historical observations. They do not show whether the activity continued after the report or whether Ferocious Kitten is active in 2026. Kaspersky did not provide a named population count for people targeted or compromised, so the samples and the period covered cannot be used to infer one.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

