APT35 — APT Profile
FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government that conducts long term, resource-intensive operations to collect strategic intelligence. APT35 typically targets U.S. and the Middle Eastern military, diplomatic and government personnel, organizations in the media, energy and defense industrial base (DIB), and engineering, business services and telecommunications sectors.Also tracked as
Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, Mint Sandstorm, Educated Manticore, Dune Ion
Tools & malware
- apk.little_looter Mobile Malware
- CharmPower Backdoor
- PowerLess Backdoor
- PowerLess Loader Loader
- POWERSTAR Backdoor
- win.chairsmack Backdoor
- win.disttrack Wiper
- win.downpaper Backdoor
- win.drokbk Backdoor
- win.leash Backdoor
- win.mediapi Backdoor
- win.mpkbot Backdoor
- win.pupy Backdoor
- win.stonedrill Backdoor
- win.syskit Backdoor
- win.telegram_grabber Backdoor
Vendor research
- Unit 42 Unit 42
- Educated Manticore - Iran Aligned Threat Actor Targeting Israel via Improved Arsenal of Tools Check Point Research
- Iranian Educated Manticore Targets Leading Tech Academics Check Point Research
- Educated Manticore Reemerges: Iranian Spear-Phishing Campaign Targeting High-Profile Figures Check Point Software
- Check Point Research uncovers rare techniques used by Iranian-affiliated threat actor, targeting Israeli entities Check Point Software
- The Kittens Are Back in Town2 - Charming Kitten Campaign KeepsGoing on, Using New Impersonation Methods ClearSky Research Team
- The Kittens Are Back in Town 3 - Charming Kitten Campaign Evolved and Deploying Spear-Phishing link by WhatsApp ClearSky Research Team
- Newscaster Threat Uses Social Media for Intelligence Gathering Kerner, S
- Magic Hound Campaign Attacks Saudi Targets Lee, B. and Falcone, R
- Mandiant M-Trends 2018 Mandiant
- New steps to protect customers from hacking Burt, T
- Operation SpoofedScholars: A Conversation with TA453 Miller, J. et al
- BadBlood: TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns Miller, J. et al
- COBALT ILLUSION Threat Profile Secureworks
- MICROSOFT CORPORATION v. JOHN DOES 1-2, CONTROLLING A COMPUTER NETWORK AND THEREBY INJURING PLAINTIFF AND ITS CUSTOMERS US District Court of DC
- New Research Exposes Iranian Threat Group Operations Wikoff, A. Emerson, R
- How Microsoft names threat actors Microsoft
- Cyberattacks target international conference attendees Burt, T
- Charming Kitten’s Christmas Gift Certfa Labs
- APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit Check Point
- Charming Kitten ClearSky Cyber Security