Latest Update27/08/2026

Threats Feed

  1. Public

    Charming Kitten Targets Global Sectors with Sponsor Backdoor

    Charming Kitten, an Iran nexus threat actor group, used the Sponsor backdoor to target 34 entities across Brazil, Israel, and UAE. Initial access was gained by exploiting Microsoft Exchange vulnerabilities (CVE-2021-26855). The campaign targeted various sectors, including automotive, communications, engineering, financial services, healthcare, insurance, legal, manufacturing, retail, technology, and telecommunications. Sponsor backdoor, disguised as an updater program, used discreetly deployed batch files to evade detection. Charming Kitten also deployed tools like Plink, Merlin agent, Mimikatz, and Meterpreter reverse shells.

    read more about Charming Kitten Targets Global Sectors with Sponsor Backdoor
  2. Public

    German Authorities Warn of Charming Kitten Cyberespionage Against Exiled Iranians

    Charming Kitten has intensified its cyber espionage operations targeting Iranian dissidents, legal professionals, journalists, and human rights activists in Germany and abroad. According to the German BfV, the group uses detailed social engineering and spoofed online identities to initiate contact and build trust. Victims are lured into video calls via phishing links that mimic legitimate platforms like Google or Microsoft. These links lead to credential-harvesting sites, often intercepting two-factor authentication as well. Stolen credentials are then used to access cloud services and extract personal data using tools like Google Takeout.

    read more about German Authorities Warn of Charming Kitten Cyberespionage Against Exiled Iranians
  3. Public

    Decoding Charming Kitten's POWERSTAR Deployment in Recent Cyber Attack

    The Iranian cyber-espionage group, Charming Kitten, targeted an individual who published an article about Iran. The attackers impersonated a reporter and carried out a series of seemingly benign interactions before sending a malicious RAR file containing the POWERSTAR backdoor. The backdoor, once executed, collects system information and communicates with a command-and-control server via encrypted channels. The attackers employ several modules for system reconnaissance, establishing persistence, and cleaning up forensic evidence. Notably, they leveraged the InterPlanetary File System (IPFS) as a fallback mechanism for command-and-control communication.

    read more about Decoding Charming Kitten's POWERSTAR Deployment in Recent Cyber Attack
  4. Public

    Unveiling BellaCiao: Charming Kitten's Sophisticated Malware Tailored For Individuals

    Charming Kitten group's latest malware, BellaCiao, targets Microsoft Exchange servers across the United States, Europe, the Middle East (Turkey), and India. The malware uses a unique communication approach with its command-and-control infrastructure and is tailored to suit individual targets. BellaCiao is a dropper malware that delivers other payloads based on instructions from the C2 server. The initial infection vector is suspected to be Microsoft Exchange exploit chains, and the malware establishes persistence by masquerading as legitimate Microsoft Exchange server processes.

    read more about Unveiling BellaCiao: Charming Kitten's Sophisticated Malware Tailored For Individuals
  5. Public

    TA453 Phishing Campaign Targets UK Government and Academia

    TA453, also known as Charming Kitten, has targeted sectors such as academia, defence, government, NGOs, think tanks and journalists in the UK and other regions of interest. The group uses spear phishing attacks, using open source reconnaissance to create tailored phishing emails. These emails are often sent from fake social media profiles or compromised email accounts. Once a relationship has been established, TA453 directs victims to malicious links or documents and steals credentials upon interaction. The group also exploits compromised email accounts to steal sensitive data, set up mail forwarding rules and facilitate further surveillance and future attacks.

    read more about TA453 Phishing Campaign Targets UK Government and Academia
  6. Public

    Charming Kitten's Cyber Arsenal: Tools and Techniques Explained

    The Iranian APT group, Charming Kitten (APT35), targets human rights activities, academia, media organizations, and political entities in the US and Central Eastern countries. Notable attacks include the 2017 HBO hack, which led to leaked unaired TV episodes, and interference attempts in the 2019 US elections, primarily targeting email accounts. Tools used by APT35 include DownPaper, which utilizes PowerShell and registry manipulation, Mimikatz for credential dumping, PsExec for remote execution, and PupyRAT for cross-platform control via phishing techniques.

    read more about Charming Kitten's Cyber Arsenal: Tools and Techniques Explained
  7. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  8. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  9. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  10. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  11. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  12. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  13. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists
  14. Public

    Charming Kitten's HYPERSCRAPE Tool Found Stealing User Data from Email Accounts

    A new tool called HYPERSCRAPE, discovered by Google Threat Analysis Group in December 2021, has been found to be used by Charming Kitten to steal user data from Gmail, Yahoo and Microsoft Outlook accounts. HYPERSCRAPE requires the victim's account credentials to run, and once logged in, it changes the account's language settings to English, downloads messages individually as .eml files, and reverts the language back to its original settings once the inbox has been downloaded.

    read more about Charming Kitten's HYPERSCRAPE Tool Found Stealing User Data from Email Accounts
  15. Public

    Iranian APTs Exploit Media Sector for Credential Harvesting and Malware Delivery

    This Proofpoint report details the escalating targeting of journalists and media organisations by state-sponsored advanced persistent threats (APTs). The report highlights how groups linked to China (TA412, TA459), North Korea (TA404), Iran (TA453, TA456, TA457), and Turkey (TA482) are using a variety of methods, including phishing emails with malicious attachments or web beacons for reconnaissance and social media credential harvesting, to achieve their intelligence and propaganda goals. The report highlights the persistent nature of the threat, the variety of tactics used, and the importance of enhanced security measures for journalists to protect their sources and the integrity of their reporting. Ultimately, it aims to raise awareness of this specific cybersecurity threat and encourage proactive protection measures within the media sector.

    read more about Iranian APTs Exploit Media Sector for Credential Harvesting and Malware Delivery
  16. Public

    Unwrapping Charming Kitten's Holiday Phishing Campaign

    During the 2021 Christmas holidays, Iranian state-backed hackers Charming Kitten initiated a targeted phishing campaign against individuals, focusing on personal and business emails. The group used public-facing applications, such as Google services, to redirect victims through a chain of legitimate services, helping bypass security layers in email services and obfuscate their operations. They employed various fake domains and developed custom phishing pages to target a range of online services, collecting sensitive data and emails from victims.

    read more about Unwrapping Charming Kitten's Holiday Phishing Campaign
  17. Public

    Charming Kitten Uses WhatsApp and LinkedIn for Targeted Phishing Attacks

    ClearSky researchers documented a new Charming Kitten (APT35) campaign that, starting July 2020, expanded their established journalist-impersonation playbook to include WhatsApp and LinkedIn as primary contact channels — a first for this group. Attackers impersonated Persian-speaking journalists from Deutsche Welle and the Jewish Journal, initiating contact via email before moving conversations to WhatsApp using German phone numbers (+49 prefix) and voice calls to build credibility. If victims declined to share their phone number, a fake LinkedIn profile (such as "Marcy Oster" or "Helen Cooper") was used to continue the approach. The ultimate goal was credential theft: victims were invited to a fake webinar via a personalized phishing link on the legitimate Deutsche Welle domain (akademie.dw[.]de), leading to a spoofed Outlook login page that harvested university credentials, including bypassing 2FA. In some cases, a malicious file attachment was also sent via LinkedIn. Targets included Israeli academics from Haifa and Tel Aviv Universities, US government officials and former State Department employees, the Baha'i community, and COVID-19-related organizations. Each victim received a uniquely personalized phishing link tied to their specific email address. Deutsche Welle confirmed to ClearSky that none of the impersonated journalists contacted the victims.

    read more about Charming Kitten Uses WhatsApp and LinkedIn for Targeted Phishing Attacks
  18. Public

    Iranian Threat Group ITG18 Exposed: Targeting US Military and Political Campaigns

    IBM X-Force IRIS uncovered extensive details on ITG18 through operational errors. Over 40 GB of data and videos revealed ITG18’s targeting of U.S. Navy and Hellenic Navy personnel, U.S. presidential campaigns, pharmaceutical companies, and Iranian-American figures. The group employed credential harvesting, phishing, and email compromise, often using Zimbra to manage compromised accounts. ITG18's operations align with Iranian strategic interests, leveraging personal accounts to gather sensitive data on military operations and geopolitical targets. Multifactor authentication posed challenges, causing operators to pivot to new targets.

    read more about Iranian Threat Group ITG18 Exposed: Targeting US Military and Political Campaigns
  19. Public

    Charming Kitten's Phishing Campaign Targets Global Political and Human Rights Figures

    The Iranian hacking group Charming Kitten, closely associated with Iran's intelligence services, has launched a new series of phishing attacks targeting journalists, political activists, and human rights advocates. These attacks, consistent with the group's previous activities, also aim at private and government institutions, think tanks, academic institutions, and organizations linked to the Baha'i community in the United States, United Kingdom, Saudi Arabia, and Europe. The attackers use fake interview scenarios, impersonating journalists from prominent media outlets like the Wall Street Journal, to gain victims' trust and direct them to phishing sites. These sites capture sensitive information like passwords and two-factor authentication codes. The campaign also involves a backdoor malware named "pdfreader.exe", which alters system settings for remote access and data exfiltration.

    read more about Charming Kitten's Phishing Campaign Targets Global Political and Human Rights Figures
  20. Public

    Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence

    ClearSky's October 2019 report documented an active Charming Kitten (APT35/Phosphorus) campaign targeting US presidential campaign staff, government officials, journalists, Iranian dissidents, and civil society figures including the Baha'i community. The campaign used four distinct impersonation vectors: fake Google Drive sharing links, SMS phishing messages, spoofed account login-attempt alerts, and fake social network profiles impersonating known contacts. Malicious links led to credential-harvesting pages mimicking Google, Yahoo, Facebook, and Instagram logins, hosted on a network of actor-registered domains. The group abused Google Sites and URL shorteners to obfuscate malicious destinations. Microsoft identified 99 domains tied to the operation (tracked internally as Phosphorus/Strontium) and obtained a court order to seize them. IOC overlaps with prior Certfa reporting confirm continuity of infrastructure across Charming Kitten campaigns dating to 2018. The campaign is assessed as part of Iran's broader effort to conduct cyber-enabled political intelligence collection ahead of the 2020 US presidential election.

    read more about Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence
  21. Public

    Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence

    ClearSky's October 2019 report documented an active Charming Kitten (APT35/Phosphorus) campaign targeting US presidential campaign staff, government officials, journalists, Iranian dissidents, and civil society figures including the Baha'i community. The campaign used four distinct impersonation vectors: fake Google Drive sharing links, SMS phishing messages, spoofed account login-attempt alerts, and fake social network profiles impersonating known contacts. Malicious links led to credential-harvesting pages mimicking Google, Yahoo, Facebook, and Instagram logins, hosted on a network of actor-registered domains. The group abused Google Sites and URL shorteners to obfuscate malicious destinations. Microsoft identified 99 domains tied to the operation (tracked internally as Phosphorus/Strontium) and obtained a court order to seize them. IOC overlaps with prior Certfa reporting confirm continuity of infrastructure across Charming Kitten campaigns dating to 2018. The campaign is assessed as part of Iran's broader effort to conduct cyber-enabled political intelligence collection ahead of the 2020 US presidential election.

    read more about Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence
  22. Public

    Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign

    The Iranian APT group Charming Kitten (APT35) conducted a cyberespionage campaign targeting academic researchers, human rights activists, media personnel, and public figures across the Middle East, US, UK, and France. Using spearphishing emails and fake websites mimicking Google and Instagram, the group sought to steal credentials and track email activity. They also impersonated journalists and researchers to deceive victims into sharing sensitive information. Key targets included Iranian dissidents, non-Iranian researchers focused on Iran, and influential public figures. The campaign employed social engineering, custom infrastructure, and domain impersonation, leveraging hosting services in Bulgaria and Germany. Notable tactics included phishing for credentials and redirecting victims to decoy domains.

    read more about Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign
  23. Public

    Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign

    The Iranian APT group Charming Kitten (APT35) conducted a cyberespionage campaign targeting academic researchers, human rights activists, media personnel, and public figures across the Middle East, US, UK, and France. Using spearphishing emails and fake websites mimicking Google and Instagram, the group sought to steal credentials and track email activity. They also impersonated journalists and researchers to deceive victims into sharing sensitive information. Key targets included Iranian dissidents, non-Iranian researchers focused on Iran, and influential public figures. The campaign employed social engineering, custom infrastructure, and domain impersonation, leveraging hosting services in Bulgaria and Germany. Notable tactics included phishing for credentials and redirecting victims to decoy domains.

    read more about Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign
  24. Public

    Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign

    The Iranian APT group Charming Kitten (APT35) conducted a cyberespionage campaign targeting academic researchers, human rights activists, media personnel, and public figures across the Middle East, US, UK, and France. Using spearphishing emails and fake websites mimicking Google and Instagram, the group sought to steal credentials and track email activity. They also impersonated journalists and researchers to deceive victims into sharing sensitive information. Key targets included Iranian dissidents, non-Iranian researchers focused on Iran, and influential public figures. The campaign employed social engineering, custom infrastructure, and domain impersonation, leveraging hosting services in Bulgaria and Germany. Notable tactics included phishing for credentials and redirecting victims to decoy domains.

    read more about Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign