Threats Feed|Charming Kitten|Last Updated 28/01/2026|AuthorCertfa Radar|Publish Date03/07/2018

Iranian APT Charming Kitten Mimics ClearSky in Phishing Scheme

  • Actor Motivations: Exfiltration
  • Attack Vectors: Phishing
  • Attack Complexity: Low
  • Threat Risk: Low Impact/High Probability

Threat Overview

The Iranian APT group Charming Kitten impersonated Israeli cybersecurity firm ClearSky by creating a phishing website that mimicked the legitimate Clearskysec.com domain. The fake site, hosted on an older compromised server, replicated ClearSky's public web pages and included phishing login options to harvest credentials. ClearSky identified the incomplete site, which was taken down before it could affect any victims. Charming Kitten has previously targeted academic researchers, human rights activists, media outlets and political consultants in Iran, the US, UK and Israel. Known for spear-phishing, impersonating organisations, and deploying malware such as DownPaper, this campaign underscores the ongoing threat to security researchers and geopolitical targets.

Detected Targets

TypeDescriptionConfidence
CaseClearSky
Cyber security and threat intelligence company. ClearSky has been targeted by Charming Kitten with abusive purposes.
Verified
SectorInformation Technology
Unknown
RegionIsrael
Unknown
RegionUnited States
Unknown

Extracted IOCs

  • clearskysecurity[.]net
download

Tip: 1 related IOCs (0 IP, 1 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

About Affiliation
Charming Kitten
Charming Kitten is an Iranian state-sponsored threat actor linked to the Islamic Revolutionary Guard Corps (IRGC) and active since at least 2012. The group conducts cyber espionage operations primarily targeting journalists, academics, political dissidents, think tank researchers, activists, and government officials across the Middle East, Europe, and the United States. Charming Kitten is best known for sustained credential phishing campaigns using fake login pages and social engineering, alongside the exploitation of known vulnerabilities in enterprise software. The cluster is tracked under numerous aliases across the industry including APT35, Magic Hound, Mint Sandstorm, and Phosphorus.
View Charming Kitten's Insights