APT35 — APT Profile
APT35 is among the most persistent Iranian espionage operations in public reporting, tracked variously as Charming Kitten, as Phosphorus and later Mint Sandstorm by Microsoft, TA453 by Proofpoint, and Magic Hound by Palo Alto Networks. FireEye, now Mandiant, dated the group's operations to 2014 and linked it to the earlier Newscaster activity; MITRE ATT&CK, which catalogues it as G0059, assesses that it probably answers to Iran's Islamic Revolutionary Guard Corps. Its collection priorities are strategic rather than opportunistic, running to military, diplomatic and government staff across the United States, Europe and the Middle East, plus media, energy, the defence industrial base, engineering firms, business services and telecoms — and, per MITRE, academics, journalists and the World Health Organization. Credential phishing is the signature technique, executed with unusual patience through elaborate personas, as in the SpoofedScholars and BadBlood campaigns MITRE records; Certfa's late-2018 research found the operators specifically soliciting two-step verification codes to get past multi-factor protections. Microsoft reported that between August and September 2019 it watched the cluster make over 2,700 attempts to fingerprint consumer email accounts tied to named targets, then attack 241 of them. Post-compromise the group mixes custom implants such as CharmPower and PowerLess with the open-source PupyRAT, Mimikatz and Metasploit, according to MITRE ATT&CK.Also tracked as
Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, Mint Sandstorm, Educated Manticore, Dune Ion, Parastoo, iKittens, NewsBeef, G0058, CharmingCypress
IntelFusions coverage (3)
- APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents 2026-02-16 · Nation-State
- APT35 Infrastructure Analysis Exposes Phishing Campaign Targeting Egyptian Shipping and Israeli Pipeline Interests 2026-02-16 · Nation-State
- Magic Hound Campaign Targets Saudi Energy, Government, and Technology Sectors with Five Custom Tools and Ties to Rocket Kitten 2026-02-16 · Nation-State
Tools & malware
- apk.little_looter Mobile Malware
- CharmPower Backdoor
- PowerLess Backdoor
- PowerLess Loader Loader
- POWERSTAR Backdoor
- win.chairsmack Backdoor
- win.disttrack Wiper
- win.downpaper Backdoor
- win.drokbk Backdoor
- win.leash Backdoor
- win.mediapi Backdoor
- win.mpkbot Backdoor
- win.pupy Backdoor
- win.stonedrill Backdoor
- win.syskit Backdoor
- win.telegram_grabber Backdoor
Vendor research
- COBALT ILLUSION Threat Profile Secureworks
- Unit 42 Unit 42
- Educated Manticore - Iran Aligned Threat Actor Targeting Israel via Improved Arsenal of Tools Check Point Research
- Iranian Educated Manticore Targets Leading Tech Academics Check Point Research
- Educated Manticore Reemerges: Iranian Spear-Phishing Campaign Targeting High-Profile Figures Check Point Software
- Check Point Research uncovers rare techniques used by Iranian-affiliated threat actor, targeting Israeli entities Check Point Software
- The Kittens Are Back in Town 3 - Charming Kitten Campaign Evolved and Deploying Spear-Phishing link by WhatsApp ClearSky Research Team
- Newscaster Threat Uses Social Media for Intelligence Gathering Kerner, S
- Magic Hound Campaign Attacks Saudi Targets Lee, B. and Falcone, R
- Mandiant M-Trends 2018 Mandiant
- How Microsoft names threat actors Microsoft
- New steps to protect customers from hacking Burt, T
- BadBlood: TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns Miller, J. et al
- MICROSOFT CORPORATION v. JOHN DOES 1-2, CONTROLLING A COMPUTER NETWORK AND THEREBY INJURING PLAINTIFF AND ITS CUSTOMERS US District Court of DC
- New Research Exposes Iranian Threat Group Operations Wikoff, A. Emerson, R
- COBALT ILLUSION Threat Profile Secureworks
- Operation SpoofedScholars: A Conversation with TA453 Miller, J. et al
- Cyberattacks target international conference attendees Burt, T
- Charming Kitten’s Christmas Gift Certfa Labs
- APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit Check Point
- Charming Kitten ClearSky Cyber Security
- The Kittens Are Back in Town2 - Charming Kitten Campaign KeepsGoing on, Using New Impersonation Methods ClearSky Research Team
Countries linked to this actor
- Iran origin
- Israel targets
- United Kingdom targets
- United States targets
- United Arab Emirates targets
- Lebanon targets