Domestic Kitten (APT-C-50) is an Iran-nexus mobile-surveillance operation, documented by Check Point since 2018, that uses fake Android apps and the FurBall spyware to monitor Iranian citizens, dissidents, ethnic minorities, and regional individuals of interest to the Iranian state.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Domestic Kitten was first detailed by Check Point Research in 2018 and revisited in an in-depth February 2021 report; Qihoo 360 tracks the cluster as APT-C-50. It is assessed with medium confidence as an Iranian state-directed operation (linked in reporting to MOIS/IRGC intelligence interests), distinguished by a domestic-repression mission rather than foreign strategic espionage. The group has no MITRE Group ID, flagged here.
The operation's tradecraft centers on mobile surveillance via social engineering: fake or trojanized Android applications — impersonating security utilities, regional news, wallpaper apps, or restaurant/service apps, and in some cases Iranian-market lookalikes — that carry the FurBall spyware (a mobile RAT derived from a commercial monitoring product). FurBall harvests SMS, call logs, contacts, location, media, and can record audio, providing comprehensive tracking of targeted individuals; Check Point also documented related Windows-based tooling. Distribution has used fake app stores, phishing, Iranian messaging channels, and SMS lures.
MENA relevance is defined by its victimology: Domestic Kitten overwhelmingly targets individuals inside Iran and the diaspora — dissidents, ethnic minorities (including Kurds), opposition figures, and other persons deemed threats by the regime — alongside some regional targets. Check Point assessed thousands of victims across multiple campaigns, making it a leading example of an Iranian internal-surveillance actor.
Domestic Kitten activity has continued into the early 2020s, with campaigns and updated FurBall variants reported through 2021-2023, so it is assessed as active. It is included as a net-new Iranian mobile-surveillance historical-through-current entry, flagged medium confidence and G-ID-less.