APT35 — APT Profile

APT35 is among the most persistent Iranian espionage operations in public reporting, tracked variously as Charming Kitten, as Phosphorus and later Mint Sandstorm by Microsoft, TA453 by Proofpoint, and Magic Hound by Palo Alto Networks. FireEye, now Mandiant, dated the group's operations to 2014 and linked it to the earlier Newscaster activity; MITRE ATT&CK, which catalogues it as G0059, assesses that it probably answers to Iran's Islamic Revolutionary Guard Corps. Its collection priorities are strategic rather than opportunistic, running to military, diplomatic and government staff across the United States, Europe and the Middle East, plus media, energy, the defence industrial base, engineering firms, business services and telecoms — and, per MITRE, academics, journalists and the World Health Organization. Credential phishing is the signature technique, executed with unusual patience through elaborate personas, as in the SpoofedScholars and BadBlood campaigns MITRE records; Certfa's late-2018 research found the operators specifically soliciting two-step verification codes to get past multi-factor protections. Microsoft reported that between August and September 2019 it watched the cluster make over 2,700 attempts to fingerprint consumer email accounts tied to named targets, then attack 241 of them. Post-compromise the group mixes custom implants such as CharmPower and PowerLess with the open-source PupyRAT, Mimikatz and Metasploit, according to MITRE ATT&CK.

Also tracked as

Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, Mint Sandstorm, Educated Manticore, Dune Ion, Parastoo, iKittens, NewsBeef, G0058, CharmingCypress

IntelFusions coverage (3)

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions