MITRE ATT&CK
RedHook in ATT&CK
21 distinct techniquesReporting
Research mentioning RedHook
Hacking group updates Furball Android spyware to evade detection
Researchers reported that the Iranian-linked Domestic Kitten surveillance operation, also tracked as APT-C-50, deployed an updated version of its FurBall Android spyware in campaigns targeting Iranian citizens. The malware was delivered through fake websites impersonating legitimate services, including a spoofed English-to-Persian translation site that served a malicious APK named sarayemaghale.apk. Analysis found the newer FurBall variant preserved core spying capabilities while adding obfuscation and refreshed command-and-control infrastructure, helping it evade antivirus detection more effectively than earlier samples. Domestic Kitten has been tied to a broader long-running surveillance program that used tailored Android apps to monitor specific ethnic, political, and religious groups, including Kurds, Sunni Muslims, ISIS supporters, and other Iranian targets. Earlier research linked the operation to hundreds of victims and showed the spyware could steal screenshots, messages, call logs, ambient audio, contacts, and files from infected devices. In the latest sample, the app requested only contacts and storage permissions—likely to reduce suspicion—while polling its C2 server over HTTP every 10 seconds, underscoring the group’s continued focus on covert mobile surveillance.