Fox Kitten (Pioneer Kitten) is an Iran-nexus group active since 2017 that specializes in exploiting internet-facing VPN and edge appliances for initial access, targeting oil-and-gas, government, defense, and technology organizations across Israel, the Gulf, and globally — and since 2020 monetizing access as a ransomware affiliate and access broker.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Fox Kitten was detailed by ClearSky in February 2020 ('Fox Kitten Campaign') and tracked by CrowdStrike as Pioneer Kitten, Dragos as Parisite, and Microsoft as Lemon Sandstorm; MITRE consolidates it as G0117. It is assessed with medium-high confidence as Iran-nexus, and is notable for blending state-directed espionage with financially motivated ransomware-affiliate activity — a dual-hat posture confirmed by CISA advisories.
The group's signature is rapid weaponization of known vulnerabilities in VPNs and network edge devices — including Pulse Secure, Fortinet FortiOS, Palo Alto Global Protect, Citrix, and later Check Point and Ivanti products — to gain initial access, followed by web shells, credential theft, RDP, and open-source tunneling tools for persistence and lateral movement. CISA's 2020 AA20-259A and 2024 AA24-241A advisories document both its access operations and its collaboration with ransomware crews (NoEscape, RansomHouse, ALPHV/BlackCat), selling or leveraging footholds.
+56 more relationships — see the relationships browser.
MENA targeting is prominent: Israel is a persistent focus, with additional victims across the Gulf and North Africa in oil-and-gas, aviation, government, defense, healthcare, engineering, and technology. The ClearSky reporting emphasized Israeli victims and the group's role as an initial-access provider feeding other Iranian operations.
Fox Kitten remains active into 2025-2026, continuing to exploit newly disclosed edge-device vulnerabilities and to broker/monetize access. Its persistence and rapid n-day exploitation make it one of the most operationally relevant Iranian access actors, and it is included here as a net-new historical-through-current entry.
Curated links to related activity — not this actor's alias list. Claimed personas are marked unverified; overlap / subgroup edges describe a related but distinct cluster, never the same actor.