Actors Insights|Latest update24/07/2026

Magic Hound

Named by Palo AltoSuspected state sponsor: Islamic Republic of Iran

Magic Hound is Palo Alto Networks Unit 42's designation for the Iranian state-sponsored threat actor known as Charming Kitten and APT35. Active since at least 2014, the group has targeted organizations in Saudi Arabia and across the Middle East, as well as government, defense, and academic targets globally. Magic Hound is characterized by its use of IRC-based malware, spear phishing campaigns, and exploitation of vulnerabilities such as Log4Shell and ProxyShell in enterprise systems. Unit 42 has documented the group's rapid adaptation of newly disclosed vulnerabilities for initial access into targeted environments.

First Seen:Jan 2014
Last Seen:Mar 2025
Indexed Reports:1
Public IOCs:80
Cluster: Charming KittenMitre: Magic HoundMisp: APT35
also known as:
Newscaster Team (Symantec)Magic Hound (Palo Alto)G0059 (Mitre)PHOSPHORUS (Microsoft)Mint Sandstorm (Microsoft)TunnelVision (SentinelOne)COBALT MIRAGE (SecureWorks)Agent SerpensAPT35 (Mandiant)TA453 (Proofpoint)COBALT ILLUSION (SecureWorks)Charming Kitten (CrowdStrike)ITG18 (IBM)

Targeted Regions

Saudi Arabia
SA
Saudi Arabia
Saudi Arabia
May 2016 ~ Feb 2017
May 2016 ~ Feb 2017
May 2016 ~ Feb 2017
Jan 2016Jul 2026

Targeted Sectors

Government Agencies and ServicesInformation TechnologyEnergy

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.