Actors Insights|Latest update04/07/2026

Agent Serpens

Named by Palo AltoSuspected state sponsor: Islamic Republic of Iran

Agent Serpens is a Unit 42 tracking name for Iranian APT activity assessed with moderate confidence to overlap with APT35 and Charming Kitten, linked to the IRGC. Active since at least 2015, the group is known for sophisticated social engineering and spear phishing campaigns targeting Iranian dissidents, journalists, and activists, particularly those living abroad in Germany and Western Europe. A 2025 campaign documented by Unit 42 involved a fraudulent website impersonating Germany's Mega Model Agency, embedding obfuscated JavaScript to profile visitors via WebRTC IP leaks and canvas fingerprinting. The group's broader toolkit includes custom backdoors such as SnailResin, SlugResin, and Sponsor alongside credential harvesting kits like GCollection. Agent Serpens also incorporates AI-assisted social engineering, including GenAI-enhanced phishing documents, reflecting rapid capability evolution consistent with broader Charming Kitten cluster tradecraft.

First Seen:Feb 2025
Last Seen:May 2025
Indexed Reports:1
Public IOCs:6
Cluster: UnclassifiedMisp: APT35
also known as:
Newscaster Team (Symantec)Magic Hound (Palo Alto)G0059 (Mitre)PHOSPHORUS (Microsoft)Mint Sandstorm (Microsoft)TunnelVision (SentinelOne)COBALT MIRAGE (SecureWorks)Agent SerpensAPT35 (Mandiant)

Targeted Regions

Germany
DE
Germany
Germany
Feb 2025 ~ May 2025
Feb 2025 ~ May 2025
Feb 2025 ~ May 2025
Feb 2025 ~ May 2025
Jan 2025Dec 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.