GreenCharlie
Named by Recorded FutureSuspected state sponsor: Islamic Republic of IranGreenCharlie is Recorded Future's designation for an Iranian threat cluster overlapping with APT42, active since at least 2024. The group focuses on credential harvesting and phishing operations targeting US political figures, government officials, and campaign-related organizations — most notably documented during the 2024 US presidential election cycle. GreenCharlie uses typosquatted domains and fake login portals to steal credentials and gain access to email and cloud accounts. The cluster shares infrastructure, tooling, and targeting patterns consistent with the broader APT42 and Mint Sandstorm tracking identities.
Targeted Regions
United StatesUnited States
Jun 2024 ~ Aug 2024
Jun 2024 ~ Aug 2024
Jun 2024 ~ Aug 2024
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.