Actors Insights|Latest update04/07/2026

GreenCharlie

Named by Recorded FutureSuspected state sponsor: Islamic Republic of Iran

GreenCharlie is Recorded Future's designation for an Iranian threat cluster overlapping with APT42, active since at least 2024. The group focuses on credential harvesting and phishing operations targeting US political figures, government officials, and campaign-related organizations — most notably documented during the 2024 US presidential election cycle. GreenCharlie uses typosquatted domains and fake login portals to steal credentials and gain access to email and cloud accounts. The cluster shares infrastructure, tooling, and targeting patterns consistent with the broader APT42 and Mint Sandstorm tracking identities.

First Seen:Jun 2024
Last Seen:Jun 2025
Indexed Reports:1
Public IOCs:141
Cluster: APT42
also known as:
GreenCharlie (Recorded Future)

Targeted Regions

United States
US
United States
United States
Jun 2024 ~ Aug 2024
Jun 2024 ~ Aug 2024
Jun 2024 ~ Aug 2024
Jan 2024Nov 2026

Targeted Sectors

Government Agencies and ServicesPolitical

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.