Rocket Kitten is an IRGC-assessed Iranian espionage group active in 2014-2015, documented by Check Point, Trend Micro, and ClearSky for aggressive spearphishing and credential-theft operations against Israeli and Saudi defense, academic, diplomatic, and dissident targets. No MITRE Group ID is assigned.
Rocket Kitten was detailed by Trend Micro (Operation Woolen-Goldfish, 2015) and Check Point ('Rocket Kitten: A Campaign With Nine Lives', November 2015), which mapped its infrastructure and identified operators plausibly linked to the IRGC. Attribution is medium confidence — the Iranian nexus is well supported by targeting and Persian-language artifacts, but Rocket Kitten has no formal MITRE Group ID and vendors note overlaps with adjacent clusters (Ajax Security Team, and later Charming Kitten), so sub-cluster boundaries are fluid.
The group's tradecraft centered on persistent, personalized spearphishing and credential-phishing (fake login pages, spoofed webmail), delivering the GHOLE/CWoolger keylogger and the Woolen-Goldfish malware. Check Point's exposure of a misconfigured attacker database revealed a large victim list and shed light on the operators' identities and manual, high-touch targeting style.
MENA targeting was prominent: victims included Israeli scientists, defense and academic figures, and diplomats, alongside Saudi Arabian targets and regional dissidents, journalists, and human-rights activists — consistent with IRGC intelligence priorities during heightened Iran-Israel and Iran-Gulf tensions.
Rocket Kitten faded after 2015 following its public exposure, and is assessed as retired under this name; its personnel and tradecraft are widely believed to have fed into the Charming Kitten / APT35 ecosystem. It is included as a formative IRGC-linked historical entry, flagged as medium confidence and G-ID-less.