Actors Insights|Latest update24/07/2026

ITG18

Named by IBMSuspected state sponsor: Islamic Republic of Iran

ITG18 is IBM X-Force's designation for the Iranian threat cluster widely known as Charming Kitten and APT35. Active since at least 2014, the group conducts credential harvesting and espionage operations targeting journalists, NGO workers, US military personnel, and political figures. IBM has documented ITG18's use of elaborately produced phishing videos to train operators on targeting techniques, as well as its extensive use of fake login pages mimicking Google, Microsoft, and Yahoo. The cluster is assessed to operate in support of IRGC intelligence priorities.

First Seen:Jan 2014
Last Seen:Mar 2025
Indexed Reports:1
Public IOCs:0
also known as:
Magic Hound (Palo Alto)TA453 (Proofpoint)COBALT ILLUSION (SecureWorks)Charming Kitten (CrowdStrike)ITG18 (IBM)PHOSPHORUS (Microsoft)Newscaster (Symantec)APT35 (Mandiant)Mint Sandstorm (Microsoft)G0059 (Mitre)

Targeted Regions

Greece
GR
Greece
Greece
Apr 2020 ~ Jul 2020
Apr 2020 ~ Jul 2020
United States
US
United States
United States
Apr 2020 ~ Jul 2020
Apr 2020 ~ Jul 2020
Jan 2020Sep 2026

Targeted Sectors

Government Agencies and ServicesMilitaryPharmaceuticals

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.