Charming Kitten's Expanding Cyber Campaign: Phishing for Political Influence
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Credential stuffing,Phishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
ClearSky's October 2019 report documented an active Charming Kitten (APT35/Phosphorus) campaign targeting US presidential campaign staff, government officials, journalists, Iranian dissidents, and civil society figures including the Baha'i community. The campaign used four distinct impersonation vectors: fake Google Drive sharing links, SMS phishing messages, spoofed account login-attempt alerts, and fake social network profiles impersonating known contacts. Malicious links led to credential-harvesting pages mimicking Google, Yahoo, Facebook, and Instagram logins, hosted on a network of actor-registered domains. The group abused Google Sites and URL shorteners to obfuscate malicious destinations. Microsoft identified 99 domains tied to the operation (tracked internally as Phosphorus/Strontium) and obtained a court order to seize them. IOC overlaps with prior Certfa reporting confirm continuity of infrastructure across Charming Kitten campaigns dating to 2018. The campaign is assessed as part of Iran's broader effort to conduct cyber-enabled political intelligence collection ahead of the 2020 US presidential election.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Dissident | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Human Rights | Verified |
| Sector | Journalists | Verified |
| Sector | University | High |
| Region | France | Verified |
| Region | United States | Verified |
| Region | Middle East Countries | Verified |
Extracted IOCs
- bahaius[.]info
- bailment[.]org
- com-activities[.]site
- com-identifier[.]site
- com-session[.]site
- com-verifications[.]site
- customers-activities[.]site
- customers-recovery[.]site
- customers-reminder[.]info
- documentsfilesharing[.]cloud
- document-sharing[.]online
- gomyfiles[.]info
- identifier-activities[.]info
- identifier-activities[.]online
- identity-verification-service[.]info
- inbox-drive[.]info
- inbox-sharif[.]info
- magic-delivery[.]info
- mobilecontinue[.]network
- mobile-messengerplus[.]network
- notification-accountservice[.]com
- recovery-services[.]info
- recoverysuperuser[.]info
- see-us[.]info
- sessions-identifier-memberemailid[.]network
- system-services[.]site
- telagram[.]net
- uploaddata[.]info
- verification-services[.]info
- my.en-gb.home-access[.]online
- 136[.]243.195.229
- 181[.]177.59.240
- 185[.]177.59.240
- 40[.]112.253.185
- 46[.]166.151.209
- 51[.]255.157.110
- 51[.]68.200.126
- 51[.]89.229.215
Tip: 38 related IOCs (8 IP, 30 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: Certfa - January 2020
Detection (four cases): 51[.]255.157.110, bahaius[.]info, customers-activities[.]site, system-services[.]site
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions about Charming Kitten's 2019 Credential-Theft Campaign
In mid-2019, Charming Kitten (APT35), an Iranian state-aligned hacking group, launched a broad credential-theft campaign targeting US presidential campaign staff, government officials, journalists, Iranian dissidents, and civil society groups including the Baha'i community. The group used four different phishing methods simultaneously — fake Google Drive links, SMS messages, spoofed account security alerts, and fake social media profiles — all designed to lure targets into entering their passwords on fake login pages for Google, Yahoo, Facebook, and Instagram. Microsoft identified 99 domains linked to the operation and obtained a court order to seize them. ClearSky documented the campaign in their "Kittens Are Back in Town 2" report published in October 2019.
The campaign was carried out by Charming Kitten, also known as APT35 or Phosphorus, an Iranian cyberespionage group active since at least 2014. The group is widely assessed to operate on behalf of Iranian state interests, with a focus on gathering political intelligence and monitoring dissidents, journalists, and civil society organizations critical of Iran. Microsoft tracks the group internally as Phosphorus and documented their attempts to target US election-related figures as part of Iran's broader cyber-enabled political interference activities.
The primary goal was credential theft — stealing login credentials for email and social media accounts to gain access to private communications, contacts, and documents. With access to a target's inbox or social media account, Charming Kitten can monitor their activities, identify their networks, and use their accounts to approach new targets. Targeting presidential campaign staff and government officials specifically aligns with Iran's interest in collecting political intelligence and potentially influencing US policy ahead of the 2020 election.
Microsoft reported 241 attempted attacks against US presidential campaign and government staff over a single 30-day period, with at least 4 successful account compromises. Beyond the US election sphere, ClearSky documented a much broader target set including journalists, academics, Iranian dissidents in France and the Middle East, and the Baha'i community. The scale of the infrastructure — 99 identified domains — indicates a sustained, large-scale operation rather than a narrow targeted campaign.
The campaign targeted US presidential campaign staff and former government officials (including people associated with the Trump administration), journalists covering Iran, Iranian dissidents and activists abroad, the Baha'i community, and human rights organizations. These groups collectively represent Charming Kitten's core intelligence priorities: monitoring opposition to the Iranian government, tracking US political decision-making on Iran, and surveilling communities the Iranian government considers threats to its stability.
Charming Kitten used four different methods to reach targets. First, spearphishing emails with links that appeared to be Google Drive document shares but led to fake login pages. Second, SMS messages sent directly to targets' phones with similar malicious links. Third, spoofed security alert emails mimicking Google or Microsoft notifications about suspicious login attempts, designed to panic targets into "verifying" their accounts on a fake portal. Fourth, fake social media profiles that made contact with targets and sent phishing links through social platforms. All four methods ultimately directed victims to convincing fake login pages for major services, capturing credentials in real time — including bypassing two-factor authentication prompts.
US election-related targets are attractive because access to campaign communications provides advance intelligence on US policy intentions toward Iran, including sanctions relief, nuclear negotiations, and regional security. Journalists covering Iran can be monitored to track what is known about Iranian operations and to identify potential sources. Dissidents and human rights activists are targeted to identify and expose opposition networks. The Baha'i community is of interest because it is considered a political threat by the Iranian government. Together, these communities give Iran a comprehensive intelligence picture of external threats to its political and security interests.
Use phishing-resistant multi-factor authentication — hardware security keys or passkeys — rather than SMS codes, which can be intercepted by real-time phishing proxies. Never click on unexpected account security alerts or document-sharing notifications; instead, go directly to the service's website by typing the address yourself. Political campaign staff, government officials, and high-risk civil society organizations should enroll in Google's Advanced Protection Program and Microsoft's AccountGuard, which provide elevated protections designed specifically for election-related and at-risk users. Verify any unexpected Google Drive sharing link by checking the sender's actual email domain carefully. Block and report the known IOC domains, and contact your IT security team immediately if you believe you may have entered credentials on a suspicious page.