Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1533 ↗inferred | Data from Local System | Collection | FurBall exfiltrates media and files from the device (Check Point) |
| T1430 ↗inferred | Location Tracking | Collection | FurBall collects device location (Check Point) |
| T1429 ↗inferred | Audio Capture | Collection | FurBall can record audio (Check Point) |
| T1636.004 ↗inferred | Protected User Data: SMS Messages | Collection | FurBall harvests SMS messages (Check Point) |
| T1636.002 ↗inferred | Protected User Data: Call Log | Collection | FurBall harvests call logs (Check Point) |
| T1636.003 ↗inferred | Protected User Data: Contact List | Collection | FurBall harvests contacts (Check Point) |
| T1655 ↗ |
| Masquerading |
| Defense Evasion |
| apps impersonate security utilities, news and service apps (Check Point) |
| T1660 ↗inferred | Phishing | Initial Access | distributes fake/trojanized Android apps via fake stores, SMS and messaging lures (Check Point) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Domestic Kitten's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.