Listen to this Post
Introduction: A New Digital Threat Amid Iran’s Human Rights Crisis
As protests and crackdowns continue to reshape Iran’s political and social landscape, a new cyber-espionage campaign has emerged that appears designed to exploit fear, grief, and urgency. Security researchers have uncovered a malicious operation targeting individuals and organizations involved in documenting alleged human rights abuses during recent protest waves. The campaign combines emotionally manipulative lures, forged forensic data, and advanced spyware techniques, reflecting a growing convergence between cyber operations and political repression. Researchers believe this activity aligns with Iranian state security interests and marks a concerning evolution in how digital surveillance and intimidation are deployed against civil society.
Summary of the Original RedKitten and the SloppyMIO Threat
The malicious campaign, identified by the French cybersecurity firm HarfangLab, was first observed in early January 2026. Researchers obtained malware samples on January 23 and publicly shared their analysis several days later. They named the operation RedKitten, following the common cybersecurity convention for Iran-linked threat actors.
The campaign distributes carefully crafted “shock lures” aimed at people searching for information about missing persons or political dissidents. These lures arrive as password-protected 7z archives titled in Farsi to resemble official Iranian forensic medical documents. Inside are multiple malicious Excel spreadsheets claiming to list hundreds of protesters allegedly killed in Tehran between December 2025 and January 2026.
The Excel files are designed to look authoritative and deeply disturbing. They include fabricated personal details, alleged causes of death, names of security forces such as the IRGC or Basij, graphic autopsy descriptions, and body release records. A final tab urges users to enable macros, which activates the malware. Researchers noted that although the files appear detailed, they contain inconsistencies such as mismatched ages, implausible workloads for doctors, and other errors that suggest the data was fabricated for psychological impact rather than accuracy.
When macros are enabled, a hidden VBA script extracts and launches a C-based malware implant dubbed SloppyMIO. The malware name reflects its inconsistent code structure, with each infection slightly altered to evade detection. SloppyMIO uses a technique known as AppDomain Manager Injection, hijacking a legitimate Windows binary to load malicious code while appearing normal to the operating system.
To maintain persistence, the malware creates scheduled tasks that ensure it restarts on system boot or reinstalls itself if removed. For command-and-control, SloppyMIO avoids traditional suspicious servers and instead uses Telegram bots to receive instructions. It sends an initial beacon announcing a new infection and then polls for commands disguised as chat messages.
The malware also uses GitHub and Google Drive as repositories for configuration files and modular payloads. In some cases, its configuration data is hidden inside images using steganography, making detection even more difficult. Once active, SloppyMIO can steal files, execute commands, download additional malware, and establish long-term backdoors.
HarfangLab researchers observed multiple signs that the malware was at least partially developed using AI tools, including oddly named variables and automated-sounding comments. While they stopped short of definitive attribution, they identified overlaps with known Iranian state-aligned threat actors, particularly IRGC-linked groups such as Yellow Liderc (also known as Imperial Kitten or TA456).
Linguistic indicators, infrastructure choices, and reused techniques strongly suggest the operation originated from an Iran-aligned threat actor. Researchers concluded that NGOs, journalists, activists, and individuals documenting human rights abuses are the most likely targets. They also noted the attackers’ playful use of kitten imagery, possibly acknowledging the cybersecurity community’s naming conventions for Iranian hacking groups.
What Undercode Say: Analysis of RedKitten, AI Malware, and Digital Repression
The RedKitten campaign illustrates a critical shift in modern cyber-espionage: malware operations are no longer purely technical attacks but psychological weapons designed to manipulate emotions and exploit moments of social trauma. By fabricating forensic evidence tied to real protests and alleged deaths, the attackers aim to override skepticism and push victims into making one fatal click.
This campaign shows how effective social engineering becomes when paired with politically relevant narratives. Activists, journalists, and families searching for missing loved ones are already under emotional strain. Presenting them with what appears to be leaked official forensic data creates urgency and trust simultaneously. This tactic mirrors previous Iran-aligned operations, where emotional hooks were used to bypass technical defenses.
The use of Excel macros remains notable. Despite years of warnings, macro-based malware continues to succeed because Office documents still represent familiarity and legitimacy in professional and activist circles. RedKitten reinforces that macros are not an outdated threat but a reliable delivery method when paired with convincing content.
SloppyMIO’s architecture reflects a broader trend toward “living off the land” techniques. By hijacking legitimate Windows binaries and relying on trusted platforms like GitHub, Google Drive, and Telegram, the malware blends into normal network traffic. This significantly raises the bar for detection, particularly in environments with limited security monitoring.
Perhaps most striking is the apparent use of large language models during malware development. The inconsistencies, unusual variable names, and semi-automated structure suggest attackers are experimenting with AI to accelerate coding, diversify samples, and evade signature-based defenses. This aligns with a global trend where threat actors adopt AI not for sophistication alone, but for speed and scale.
The attribution challenge highlighted by HarfangLab is also telling. As Iranian threat groups increasingly share infrastructure, tactics, and even development styles, distinguishing between them becomes harder. The adoption of AI further blurs these lines, creating a more homogeneous threat landscape where intent matters more than precise group labels.
RedKitten also underscores how cyber operations are integrated into state security strategies. Targeting human rights documentation is not random; it directly supports efforts to suppress narratives, identify dissidents, and intimidate civil society. Malware like SloppyMIO becomes a silent extension of physical repression.
From a defensive perspective, this campaign reinforces the need for non-technical communities to receive cybersecurity support. NGOs and activists often lack advanced defenses but face nation-state-level threats. Awareness training, strict macro controls, and secure document-sharing practices are no longer optional but essential.
Finally, RedKitten demonstrates that AI is not just reshaping defensive cybersecurity. Offensive operations are rapidly adapting, using automation to lower skill barriers and expand reach. The result is a more crowded, faster-moving threat ecosystem where emotionally intelligent attacks may be more dangerous than technically complex ones.
Fact Checker Results
Assessment of Technical Claims
✅ Malware delivery via Excel macros and AppDomain Manager Injection aligns with documented techniques used by Iran-aligned actors.
Assessment of Attribution Indicators
✅ Use of Telegram, GitHub, and Farsi linguistic clues is consistent with multiple Iranian APT campaigns since 2022.
Assessment of AI-Assisted Development Claims
❌ While indicators suggest LLM involvement, definitive proof of AI-generated code remains circumstantial.
Prediction: Where RedKitten-Style Campaigns Are Heading Next 🔮
🚨 Increased Targeting of Civil Society
Iran-aligned cyber operations are likely to further focus on journalists, NGOs, and diaspora groups documenting abuses.
🤖 Expanded Use of AI-Generated Lures
Future campaigns will likely use AI to generate more convincing documents, personalized messages, and multilingual content.
📡 Greater Reliance on Trusted Platforms
Attackers will continue abusing mainstream services like cloud storage and messaging apps to evade detection and attribution.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




