Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
What Happened in the RedKitten Campaign
The RedKitten cyber campaign, identified by HarfangLab in January 2026, is attributed to a Farsi-speaking threat actor linked to Iranian state interests. The campaign targets non-governmental organizations and individuals involved in documenting human rights abuses amid nationwide protests in Iran that began in late 2025. The unrest has been fueled by soaring inflation, food price increases, and currency depreciation, leading to mass casualties and an internet blackout.
The attack vector involves a 7-Zip archive with a Farsi filename containing macro-laden Microsoft Excel documents. These spreadsheets falsely claim to provide details about protesters who died in Tehran between December 22, 2025, and January 20, 2026. When users enable the embedded malicious VBA macro, it acts as a dropper for a C#-based implant, utilizing a technique known as AppDomainManager injection.
The malware, referred to as SloppyMIO, employs GitHub for configuration retrieval and Google Drive for payload delivery. It can execute commands, collect files, and maintain persistence through scheduled tasks. The use of Telegram for command-and-control communication allows the malware to send and receive instructions discreetly.
Implications for Users and Organizations
This campaign highlights the increasing sophistication of cyber threats, particularly those leveraging artificial intelligence tools to generate malicious code. The reliance on common platforms like GitHub and Google Drive complicates traditional tracking methods, making it essential for users and organizations to remain vigilant.
Individuals seeking information about missing persons should be cautious of unsolicited files and verify the authenticity of sources before enabling macros or downloading attachments. Organizations, especially those involved in human rights advocacy, should implement robust cybersecurity measures to protect sensitive information and personnel.
The RedKitten campaign serves as a reminder of the risks posed by emotional manipulation in cyber attacks, where attackers exploit distressing situations to trigger infections. Awareness and education about such tactics can help mitigate risks.
- RedKitten: A cyber campaign targeting NGOs and activists documenting human rights abuses in Iran.
- SloppyMIO: The malware used in the RedKitten campaign, capable of executing commands and maintaining persistence.
- AppDomainManager injection: A technique employed by the malware to deliver its payload.
- VBA macro: A malicious code embedded in Excel documents that initiates the infection process.
- Telegram: The platform used for command-and-control communication by the malware.
Key Takeaways
- Be cautious when opening files related to sensitive topics, especially those from unknown sources.
- Verify the authenticity of documents claiming to provide information about missing persons before enabling macros.
- Implement strong cybersecurity measures, including regular software updates and employee training on phishing tactics.
- Monitor for unusual activity in your accounts, particularly if you are involved in human rights advocacy.
- Educate yourself and your organization about the risks of emotional manipulation in cyber attacks.
Key Terms & Concepts
- RedKitten: In this article, RedKitten refers to a cyber campaign targeting NGOs and activists in Iran.
- SloppyMIO: SloppyMIO is the name of the malware used in the RedKitten campaign to execute commands and maintain persistence.
- AppDomainManager injection: This technique is used by malware to deliver its payload by injecting malicious code into a legitimate application.
- VBA macro: A VBA macro is a type of malicious code embedded in documents that can execute harmful actions when enabled.
- Telegram: Telegram is a messaging platform used by the malware for command-and-control communication.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.