Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 17:13:32 UTC Home > List all groups > List all tools > List all groups using tool SSHMinion Tool: SSHMinion Names SSHMinion Category Malware Type Tunneling Description (Crowdstrike) PIONEER KITTEN’s namesake operational characteristic is its reliance on SSH tunneling, through open-source tools such as Ngrok and the adversary’s custom tool SSHMinion, for communication with implants and hands-on-keyboard activity via Remote Desktop Protocol (RDP). Information Last change to this tool card: 02 September 2020 Download this tool card in JSON format All groups using tool SSHMinion Changed Name Country Observed APT groups Parisite, Fox Kitten, Pioneer Kitten 2017-Nov 2020 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bf8f2c1b-d55f-4e89-af5b-2a4155a6c13a https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bf8f2c1b-d55f-4e89-af5b-2a4155a6c13a Page 1 of 1