Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ferocious Kitten APT Deploying MarkiRAT to Capture Keystroke and Clipboard Logging

Ferocious Kitten APT Deploying MarkiRAT to Capture Keystroke and Clipboard Logging

Posted on November 12, 2025November 12, 2025 By CWS

Ferocious Kitten has emerged as a big cyber-espionage risk focusing on Persian-speaking people inside Iran since not less than 2015.

The Iranian-linked superior persistent risk group operates with a extremely targeted goal, using politically themed decoy paperwork to govern victims into executing weaponized recordsdata.

Over time, the group developed a classy customized implant often called MarkiRAT, which supplies intensive knowledge assortment capabilities together with keystroke logging, clipboard knowledge seize, screenshot performance, and credential harvesting with staged knowledge exfiltration via HTTP and HTTPS protocols.

The group’s assault methodology depends on spearphishing campaigns delivering malicious Microsoft Workplace paperwork embedded with Visible Primary for Purposes macros.

These crafted emails goal dissidents, activists, and people perceived as threats to the Iranian regime. As soon as a sufferer opens a weaponized doc, the embedded macros execute with user-level privileges, establishing a system foothold.

The social engineering proves remarkably efficient, as bait paperwork include anti-regime propaganda that reinforces perceived legitimacy to targets.

Following preliminary execution, the malware deploys a number of persistence mechanisms.

Picus Safety’s safety analysts recognized that MarkiRAT variants make use of subtle hijacking methods implanting the malware alongside authentic functions.

Sure variants seek for Telegram or Chrome installations, copy themselves into software directories, and modify shortcuts to execute the malware earlier than launching the authentic software.

This method stays efficient as a result of customers understand functions functioning usually after execution.

Protection Evasion and Assortment Mechanisms

The malware employs a number of evasion ways to bypass detection and safety controls. One approach includes the Proper-to-Left Override (RTLO) Unicode trick, which manipulates filename show inside file explorers.

By inserting the Unicode character U+202E into executable filenames, attackers make malicious recordsdata seem as innocent media recordsdata similar to photographs or movies.

A file named “MyVideou202E4pm.exe” shows as “MyVideoexe.mp4” to customers, dramatically growing execution likelihood amongst non-technical victims.

MarkiRAT’s assortment capabilities symbolize its core performance. The implant maintains persistent beaconing threads speaking with command-and-control servers utilizing HTTP POST and GET requests.

The malware systematically information consumer keystrokes and clipboard contents, then exfiltrates this intelligence to distant servers.

Critically, Picus Safety researchers famous that MarkiRAT targets particular credential storage codecs together with KeePass databases (.kdbx) and PGP key recordsdata (.gpg).

The malware terminates KeePass processes earlier than keystroke logging begins, forcing customers to re-enter grasp passwords, thereby capturing authentication credentials.

The group demonstrates adaptive operational safety by checking for put in safety software program similar to Kaspersky and Bitdefender.

Ferocious Kitten’s collection-focused methodology and sustained focusing on reveal a company prioritizing intelligence gathering, establishing this group as a persistent and evolving risk to Persian-speaking populations globally.

Comply with us on Google Information, LinkedIn, and X to Get Extra Immediate Updates, Set CSN as a Most well-liked Supply in Google.

Cyber Security News Tags:APT, Capture, Clipboard, Deploying, Ferocious, Keystroke, Kitten, Logging, MarkiRAT

Post navigation

Previous Post: New Quantum Route Redirect Tool Lets Attackers Launch One-Click Phishing Attacks on Microsoft 365 Users
Next Post: Chrome Patches High-severity Implementation Vulnerability in V8 JavaScript engine

Related Posts

New TAOTH Campaign Exploits End-of-Support Software to Distribute Malware and Collect Sensitive Data New TAOTH Campaign Exploits End-of-Support Software to Distribute Malware and Collect Sensitive Data Cyber Security News
The Gentlemen Ransomware: A Growing Cyber Threat The Gentlemen Ransomware: A Growing Cyber Threat Cyber Security News
Vulnerable Water Systems Face Cyber Threats Vulnerable Water Systems Face Cyber Threats Cyber Security News
Critical Cisco Flaw Allows Remote Command Execution Critical Cisco Flaw Allows Remote Command Execution Cyber Security News
New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently Cyber Security News
CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates
  • Tengu Botnet Uses Watchdog to Restart Linux Devices
  • Origin Energy Reports Data Breach Impacting 900,000 Customers
  • Cyera to Acquire Oasis Security in Billion-Dollar Deal

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates
  • Tengu Botnet Uses Watchdog to Restart Linux Devices
  • Origin Energy Reports Data Breach Impacting 900,000 Customers
  • Cyera to Acquire Oasis Security in Billion-Dollar Deal

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark