Charming Kitten Uses WhatsApp and LinkedIn for Targeted Phishing Attacks
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Honey Trap,Phishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
ClearSky researchers documented a new Charming Kitten (APT35) campaign that, starting July 2020, expanded their established journalist-impersonation playbook to include WhatsApp and LinkedIn as primary contact channels — a first for this group. Attackers impersonated Persian-speaking journalists from Deutsche Welle and the Jewish Journal, initiating contact via email before moving conversations to WhatsApp using German phone numbers (+49 prefix) and voice calls to build credibility. If victims declined to share their phone number, a fake LinkedIn profile (such as "Marcy Oster" or "Helen Cooper") was used to continue the approach. The ultimate goal was credential theft: victims were invited to a fake webinar via a personalized phishing link on the legitimate Deutsche Welle domain (akademie.dw[.]de), leading to a spoofed Outlook login page that harvested university credentials, including bypassing 2FA. In some cases, a malicious file attachment was also sent via LinkedIn. Targets included Israeli academics from Haifa and Tel Aviv Universities, US government officials and former State Department employees, the Baha'i community, and COVID-19-related organizations. Each victim received a uniquely personalized phishing link tied to their specific email address. Deutsche Welle confirmed to ClearSky that none of the impersonated journalists contacted the victims.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Deutsche Welle Deutsche Welle, commonly shortened to DW, is a German public, state-owned international broadcaster funded by the German federal tax budget. Deutsche Welle has been targeted by Charming Kitten with abusive purposes. | Verified |
| Sector | Government Agencies and Services None | High |
| Sector | Human Rights | Verified |
| Sector | Journalists | Verified |
| Sector | University | Verified |
| Region | Israel | Verified |
| Region | United States | Verified |
FAQs
Frequently Asked Questions about Charming Kitten's WhatsApp and LinkedIn Phishing Campaign
In July 2020, Charming Kitten (APT35) — an Iranian state-aligned hacking group — launched a new phishing campaign against academics, government officials, and civil society figures. For the first time, the group used WhatsApp and LinkedIn as contact channels alongside email. Attackers posed as Persian-speaking journalists from Deutsche Welle and the Jewish Journal, spending days building rapport with targets before sending them personalized phishing links hosted on a real Deutsche Welle domain. The goal was to steal institutional email credentials. In some cases, they also sent malicious file attachments via fake LinkedIn profiles. ClearSky Cyber Security uncovered and published the campaign in August 2020.
The attack was carried out by Charming Kitten, also known as APT35 or Ajax, an Iranian cyberespionage group active since at least 2014 and widely assessed to operate on behalf of Iranian state interests. The group has a long history of targeting academics, journalists, human rights activists, and government officials in the Middle East, Europe, and the United States. This campaign marked a notable evolution in their tactics, introducing social media platforms as a primary attack vector for the first time.
The primary goal was credential theft — specifically, stealing university and institutional email login credentials. With access to a target's inbox, Charming Kitten can monitor their communications, identify new targets, and exfiltrate sensitive research or correspondence. In some cases, the attackers appeared willing to shift from credential theft to direct malware infection by sending malicious file attachments, which would give them deeper, more persistent access to the victim's computer.
The campaign was targeted but broad in terms of the communities it went after. ClearSky identified attempts against Israeli academics at Haifa and Tel Aviv Universities, US government officials including former State Department employees, members of the Baha'i community, and COVID-19 research organizations including Gilead and the WHO. The group customized the webinar topic for each individual target based on their area of expertise, showing careful reconnaissance before each approach.
The primary targets were Israeli academics, US government officials, human rights defenders, the Baha'i community, and journalists. These groups are of specific interest to Iranian intelligence because they study, advocate on, or make policy decisions about Iran and the broader Middle East. Israeli researchers working on Iran-related topics, and US officials with knowledge of Iran policy, represent high-value intelligence targets for a state actor looking to monitor and influence international discourse about Iran.
The attack unfolded in three stages. First, a target received an email from someone posing as a Deutsche Welle journalist, inviting them to speak at a webinar on a topic tailored to their expertise. Second, if the target engaged, the attacker moved the conversation to WhatsApp — using a German phone number and even attempting voice calls — to build rapport and urgency over several days. Third, the target was sent a personalized phishing link on the real Deutsche Welle domain, which displayed a fake Outlook login page. When the victim entered their credentials, they were captured by the attacker. If the victim got an error, the attacker pressured them to try again, enabling the bypass of two-factor authentication prompts.
These targets hold sensitive knowledge that is directly valuable to Iranian intelligence. Israeli academics studying Iran-related security topics can inform Iran about how adversaries perceive their capabilities and intentions. US government officials and former diplomats have institutional knowledge of US policy on Iran. The Baha'i community, which faces persecution in Iran, is of interest for monitoring dissent. COVID-19 researchers at organizations like Gilead were targeted during a period when Iran was seeking access to treatments under sanctions. By compromising email accounts, Charming Kitten gains visibility into private communications across an entire network of interconnected researchers and officials.
Be skeptical of any unsolicited contact from journalists via WhatsApp or LinkedIn, especially if they ask you to click a link and log in somewhere. Legitimate journalists do not spend days pressuring sources to activate webinar invitations through WhatsApp. Always verify a journalist's identity by contacting the news organization directly using contact details from their official website — not the number or profile that reached out to you. Before entering credentials anywhere, double-check the full URL: even a link on a real domain can lead to a phishing page. Organizations should deploy phishing-resistant MFA (hardware keys or passkeys), as standard SMS-based 2FA can be bypassed when credentials are stolen in real time. Researchers and officials in communities historically targeted by Iran — Israeli academia, US foreign policy circles, Iranian diaspora, Baha'i organizations — should be especially vigilant.