Actors Insights|Latest update24/07/2026

TunnelVision

Named by SentinelOneSuspected state sponsor: Islamic Republic of Iran

TunnelVision is a threat tracking name used by SentinelOne for a Charming Kitten subgroup observed exploiting VPN vulnerabilities for initial access in early 2022. The group was documented rapidly exploiting critical flaws in Fortinet FortiOS, Pulse Connect Secure, and VMware Horizon to gain footholds in networks of interest in the Middle East and Europe. TunnelVision activity overlaps technically with the broader Charming Kitten and Mint Sandstorm cluster, sharing targeting patterns and post-exploitation tooling. The operations were noted for speed in weaponizing newly disclosed vulnerabilities, consistent with the technically mature subgroup described by Microsoft under the Mint Sandstorm name.

First Seen:Feb 2022
Last Seen:Mar 2022
Indexed Reports:2
Public IOCs:21
Cluster: Charming KittenMisp: APT35
also known as:
Newscaster Team (Symantec)Magic Hound (Palo Alto)G0059 (Mitre)PHOSPHORUS (Microsoft)Mint Sandstorm (Microsoft)TunnelVision (SentinelOne)COBALT MIRAGE (SecureWorks)Agent SerpensAPT35 (Mandiant)

Targeted Regions

Middle East
ME
Middle East
Middle East
Feb 2022 ~ Feb 2022
United States
US
United States
United States
Feb 2022 ~ Feb 2022
Jan 2022Nov 2026

Targeted Sectors

Government Agencies and ServicesTechnology

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.