Latest Update27/08/2026

Threats Feed

  1. Public

    Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine

    Leaked internal documents reveal a highly structured APT35 (Charming Kitten) operation run as a quota-driven, bureaucratic intelligence unit within the IRGC IO. The materials detail coordinated, long-term cyber-espionage campaigns targeting Lebanon, Kuwait, Turkey, Saudi Arabia, South Korea, and domestic Iranian entities, with a strong focus on diplomatic, governmental, telecom, energy, and large commercial mail systems. Operators used ProxyShell, Ivanti exploits, credential replay, HERV phishing, and persistent mailbox monitoring to harvest GALs, credentials, and sensitive communications. The leak exposes end-to-end workflows: reconnaissance, exploitation, credential theft, HUMINT-focused collection, and centralized KPI reporting, confirming a mature, state-managed espionage apparatus.

    read more about Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine
  2. Public

    Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine

    Leaked internal documents reveal a highly structured APT35 (Charming Kitten) operation run as a quota-driven, bureaucratic intelligence unit within the IRGC IO. The materials detail coordinated, long-term cyber-espionage campaigns targeting Lebanon, Kuwait, Turkey, Saudi Arabia, South Korea, and domestic Iranian entities, with a strong focus on diplomatic, governmental, telecom, energy, and large commercial mail systems. Operators used ProxyShell, Ivanti exploits, credential replay, HERV phishing, and persistent mailbox monitoring to harvest GALs, credentials, and sensitive communications. The leak exposes end-to-end workflows: reconnaissance, exploitation, credential theft, HUMINT-focused collection, and centralized KPI reporting, confirming a mature, state-managed espionage apparatus.

    read more about Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine
  3. Public

    Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine

    Leaked internal documents reveal a highly structured APT35 (Charming Kitten) operation run as a quota-driven, bureaucratic intelligence unit within the IRGC IO. The materials detail coordinated, long-term cyber-espionage campaigns targeting Lebanon, Kuwait, Turkey, Saudi Arabia, South Korea, and domestic Iranian entities, with a strong focus on diplomatic, governmental, telecom, energy, and large commercial mail systems. Operators used ProxyShell, Ivanti exploits, credential replay, HERV phishing, and persistent mailbox monitoring to harvest GALs, credentials, and sensitive communications. The leak exposes end-to-end workflows: reconnaissance, exploitation, credential theft, HUMINT-focused collection, and centralized KPI reporting, confirming a mature, state-managed espionage apparatus.

    read more about Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine
  4. Public

    Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine

    Leaked internal documents reveal a highly structured APT35 (Charming Kitten) operation run as a quota-driven, bureaucratic intelligence unit within the IRGC IO. The materials detail coordinated, long-term cyber-espionage campaigns targeting Lebanon, Kuwait, Turkey, Saudi Arabia, South Korea, and domestic Iranian entities, with a strong focus on diplomatic, governmental, telecom, energy, and large commercial mail systems. Operators used ProxyShell, Ivanti exploits, credential replay, HERV phishing, and persistent mailbox monitoring to harvest GALs, credentials, and sensitive communications. The leak exposes end-to-end workflows: reconnaissance, exploitation, credential theft, HUMINT-focused collection, and centralized KPI reporting, confirming a mature, state-managed espionage apparatus.

    read more about Inside APT35: Leaked Files Reveal Structured IRGC Cyber-Espionage Machine
  5. Public

    New Charming Kitten Operation Blends Long-Term Reconnaissance and WebSocket Phishing

    The new Charming Kitten campaign demonstrates a significant escalation in the group’s operational maturity, combining strategic impersonation, long-term reconnaissance, and a large, automated infrastructure. The attackers impersonated Pentagon official Ariane Tabatabai to target Iranian activists, initiating contact via Telegram before redirecting victims through Google Sites to credential-harvesting domains using a WebSocket-based phishing kit. Evidence shows the group monitored security researcher activity for months, preparing infrastructure from May and launching operations in late July. More than 30 previously unseen domains support the campaign, reflecting increased automation, operational scale, and real-time monitoring. The operation highlights Charming Kitten’s growing geopolitical awareness and refined social engineering capability.

    read more about New Charming Kitten Operation Blends Long-Term Reconnaissance and WebSocket Phishing
  6. Public

    Iranian APT Impersonates German Model Agency in Espionage Operation

    Suspected Iranian threat actors, likely linked to APT35 (Agent Serpens), created a fraudulent website impersonating Germany’s Mega Model Agency to conduct targeted espionage. The site collects extensive visitor data—including IP addresses, browser fingerprints, and screen resolutions—using obfuscated JavaScript to enable selective targeting. A fake model profile and inactive album link suggest planned social engineering attacks. Although no victim interaction was confirmed, the infrastructure and tactics indicate preparation for spear phishing. The campaign targets dissidents, journalists, and activists abroad, especially in Germany, aligning with the group’s history of surveillance and influence operations against Iranian opposition figures.

    read more about Iranian APT Impersonates German Model Agency in Espionage Operation
  7. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  8. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  9. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  10. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  11. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  12. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  13. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  14. Public

    APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents

    APT35 (Charming Kitten, Phosphorus, Mint Sandstorm) is an Iranian state-sponsored cyber espionage group linked to the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2014, the group has targeted U.S. government officials, political campaigns, journalists, and prominent Iranian dissidents abroad. Their tactics include spear-phishing, credential theft, malware deployment, and persistence techniques. APT35 has been involved in high-profile incidents, including the HBO breach (2017), attacks on a U.S. presidential campaign (2019), and the development of HYPERSCRAPE (2022) for email theft. Their campaigns leverage social engineering, spoofed domains, and cloud-based persistence, with operations focusing on espionage and data exfiltration.

    read more about APT35: Iran’s Cyber Espionage Unit Targeting U.S. and Dissidents
  15. Public

    APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries

    APT35 targeted the aerospace and semiconductor industries in the US, Thailand, UAE, and Israel using fake recruitment and corporate websites. These sites delivered malware via forged legitimate programs and malicious DLLs to compromise victims. The group leveraged platforms like GitHub, OneDrive, and Google Cloud for C&C communications and payload delivery. In a related attack, a semiconductor company was targeted using a VPN program laced with malicious components. Persistence mechanisms included registry modifications, while obfuscation techniques were used to evade detection. APT35’s activities are linked to the Islamic Revolutionary Guard Corps (IRGC) of Iran.

    read more about APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries
  16. Public

    APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries

    APT35 targeted the aerospace and semiconductor industries in the US, Thailand, UAE, and Israel using fake recruitment and corporate websites. These sites delivered malware via forged legitimate programs and malicious DLLs to compromise victims. The group leveraged platforms like GitHub, OneDrive, and Google Cloud for C&C communications and payload delivery. In a related attack, a semiconductor company was targeted using a VPN program laced with malicious components. Persistence mechanisms included registry modifications, while obfuscation techniques were used to evade detection. APT35’s activities are linked to the Islamic Revolutionary Guard Corps (IRGC) of Iran.

    read more about APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries
  17. Public

    APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries

    APT35 targeted the aerospace and semiconductor industries in the US, Thailand, UAE, and Israel using fake recruitment and corporate websites. These sites delivered malware via forged legitimate programs and malicious DLLs to compromise victims. The group leveraged platforms like GitHub, OneDrive, and Google Cloud for C&C communications and payload delivery. In a related attack, a semiconductor company was targeted using a VPN program laced with malicious components. Persistence mechanisms included registry modifications, while obfuscation techniques were used to evade detection. APT35’s activities are linked to the Islamic Revolutionary Guard Corps (IRGC) of Iran.

    read more about APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries
  18. Public

    APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries

    APT35 targeted the aerospace and semiconductor industries in the US, Thailand, UAE, and Israel using fake recruitment and corporate websites. These sites delivered malware via forged legitimate programs and malicious DLLs to compromise victims. The group leveraged platforms like GitHub, OneDrive, and Google Cloud for C&C communications and payload delivery. In a related attack, a semiconductor company was targeted using a VPN program laced with malicious components. Persistence mechanisms included registry modifications, while obfuscation techniques were used to evade detection. APT35’s activities are linked to the Islamic Revolutionary Guard Corps (IRGC) of Iran.

    read more about APT35 Targets Aerospace and Semiconductor Sectors Across Multiple Countries
  19. Public

    Charming Kitten’s TA455 Uses Social Engineering to Spread Malware in Aerospace Sector

    ClearSky Cyber Security's research details an Iranian cyber campaign, dubbed "Iranian Dream Job," using fake job postings to target the aerospace industry. The campaign, active since at least September 2023, employs the SnailResin malware, leading to the SlugResin backdoor. Attribution is complex, with potential links to both Iranian group TA455 (a Charming Kitten subgroup) and North Korea's Lazarus group, raising questions about potential collaboration or deception. The campaign leverages fake LinkedIn profiles and websites, distributing malware via seemingly legitimate ZIP files containing a malicious executable. This sophisticated attack uses social engineering and DLL side-loading for infiltration.

    read more about Charming Kitten’s TA455 Uses Social Engineering to Spread Malware in Aerospace Sector
  20. Public

    Charming Kitten Targets Global Sectors with Sponsor Backdoor

    Charming Kitten, an Iran nexus threat actor group, used the Sponsor backdoor to target 34 entities across Brazil, Israel, and UAE. Initial access was gained by exploiting Microsoft Exchange vulnerabilities (CVE-2021-26855). The campaign targeted various sectors, including automotive, communications, engineering, financial services, healthcare, insurance, legal, manufacturing, retail, technology, and telecommunications. Sponsor backdoor, disguised as an updater program, used discreetly deployed batch files to evade detection. Charming Kitten also deployed tools like Plink, Merlin agent, Mimikatz, and Meterpreter reverse shells.

    read more about Charming Kitten Targets Global Sectors with Sponsor Backdoor
  21. Public

    APT35's Exploitation of Microsoft Exchange: Targeting Europe, Middle East, and North America

    AttackIQ's August 2023 report profiles APT35 (also known as Charming Kitten and Phosphorus), an Iranian state-sponsored espionage group active since at least 2014. The report presents an attack graph emulating APT35's December 2021 exploitation of Microsoft Exchange ProxyShell vulnerabilities — CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 — to gain initial access across targets in Europe, the Middle East, and North America. The documented attack chain begins with web shell deployment on the compromised Exchange server, followed by scheduled task persistence, disabling of Microsoft Defender via registry modification, WDigest authentication enablement for plaintext credential capture, LSASS memory dumping via rundll32.exe and comsvcs.dll, and data exfiltration via HTTP POST requests. The group also created local accounts added to the Administrators and Remote Desktop Users groups and opened port 3389 (RDP) through Windows Firewall for persistent remote access. APT35 targets government entities, academic institutions, media organizations, defense, energy, engineering, business services, and telecommunications sectors, with a particular focus on the United States and Middle East.

    read more about APT35's Exploitation of Microsoft Exchange: Targeting Europe, Middle East, and North America
  22. Public

    Iranian APTs Exploit PaperCut Vulnerability in Global Cyber Attacks

    On May 5–8, 2023, Microsoft Threat Intelligence reported that two Iranian state-backed groups had joined an ongoing wave of attacks targeting CVE-2023-27350, a pre-authentication critical remote code execution vulnerability (CVSS 9.8) in PaperCut MF and NG print management software versions 8.0 and later. The two groups are Mango Sandstorm (also known as Mercury or MuddyWater, linked to Iran's Ministry of Intelligence and Security/MOIS) and Mint Sandstorm (also known as Phosphorus or APT35, linked to Iran's Islamic Revolutionary Guard Corps/IRGC). Mint Sandstorm's exploitation was characterized as opportunistic, targeting organizations across multiple sectors and geographies without specific victim selection. Mango Sandstorm's activity was lower-volume, with operators reusing tools from prior intrusions to connect to existing C2 infrastructure — indicating the group was extending rather than initiating campaigns. The vulnerability had been disclosed in March 2023; public PoC exploits were released shortly after, enabling rapid threat actor adoption. Earlier exploitation was attributed to Lace Tempest (linked to Clop ransomware) and separately led to LockBit ransomware deployments. CISA added CVE-2023-27350 to its Known Exploited Vulnerabilities catalog on April 21, 2023, mandating federal agencies patch by May 12. VulnCheck subsequently documented a new exploitation method that bypassed existing detections, highlighting the difficulty of detection-only defenses. PaperCut is used by over 100 million users at 70,000+ organizations including large enterprises, government bodies, and educational institutions globally. Patched versions are 20.1.7, 21.2.11, and 22.0.9 and later.

    read more about Iranian APTs Exploit PaperCut Vulnerability in Global Cyber Attacks
  23. Public

    Charming Kitten's Cyber Arsenal: Tools and Techniques Explained

    The Iranian APT group, Charming Kitten (APT35), targets human rights activities, academia, media organizations, and political entities in the US and Central Eastern countries. Notable attacks include the 2017 HBO hack, which led to leaked unaired TV episodes, and interference attempts in the 2019 US elections, primarily targeting email accounts. Tools used by APT35 include DownPaper, which utilizes PowerShell and registry manipulation, Mimikatz for credential dumping, PsExec for remote execution, and PupyRAT for cross-platform control via phishing techniques.

    read more about Charming Kitten's Cyber Arsenal: Tools and Techniques Explained
  24. Public

    Charming Kitten Exploits Phishing to Target Global Academia and Activists

    This Certfa Lab report details the cyber espionage activities of Charming Kitten (APT42), an Iranian state-sponsored hacking group. The report focuses on four specific operations ("Alfa," "Bravo," "Charlie," and "Delta"), illustrating how Charming Kitten uses sophisticated social engineering, primarily impersonating prominent individuals on LinkedIn and Twitter, to build trust with targets before delivering malicious links disguised as innocuous meeting requests or research materials. The attacks consistently leverage phishing to steal credentials, targeting researchers, academics, activists, and journalists with a particular focus on the Middle East and North Africa. The report aims to raise public awareness of Charming Kitten's tactics and provide recommendations for enhancing online security, particularly emphasizing the use of multi-factor authentication.

    read more about Charming Kitten Exploits Phishing to Target Global Academia and Activists