Actors Insights|Latest update24/07/2026

iKittens

Named by Iran ThreatsSuspected state sponsor: Islamic Republic of Iran

iKittens is an early FireEye tracking designation for activity later consolidated into the Charming Kitten cluster. The name was used to describe Iranian-linked social media persona operations and spear phishing campaigns targeting US government and military personnel, journalists, and defense contractors, primarily between 2016 and 2017. The group's approach involved establishing fake social media identities to build trust with targets before delivering phishing content. This operational pattern prefigures the sophisticated social engineering tradecraft consistently documented across the broader Charming Kitten/APT35 cluster.

First Seen:Oct 2016
Last Seen:Feb 2017
Indexed Reports:1
Public IOCs:6
also known as:
Newscaster (Symantec)Parastoo (Flashpoint)iKittens (Iran Threats)Group 83 (Talos)NewsBeef (Kaspersky)G0058 (Mitre)CharmingCypress (Volexity)Mint Sandstorm (Microsoft)Charming Kitten (CrowdStrike)

Targeted Regions

United States
US
United States
United States
Oct 2016 ~ Feb 2017
Oct 2016 ~ Feb 2017
Jan 2016Jul 2026

Targeted Sectors

DefenseHuman Rights

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.