Charming Kitten's Phishing Campaign Targets Global Political and Human Rights Figures
- Actor Motivations: Espionage
- Attack Vectors: Backdoor,Malware,Pretexting,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: Low Impact/Low Probability
Threat Overview
The Iranian hacking group Charming Kitten, closely associated with Iran's intelligence services, has launched a new series of phishing attacks targeting journalists, political activists, and human rights advocates. These attacks, consistent with the group's previous activities, also aim at private and government institutions, think tanks, academic institutions, and organizations linked to the Baha'i community in the United States, United Kingdom, Saudi Arabia, and Europe. The attackers use fake interview scenarios, impersonating journalists from prominent media outlets like the Wall Street Journal, to gain victims' trust and direct them to phishing sites. These sites capture sensitive information like passwords and two-factor authentication codes. The campaign also involves a backdoor malware named "pdfreader.exe", which alters system settings for remote access and data exfiltration.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Farnaz Fassihi Farnaz Fassihi is an Iranian-American journalist who has worked for The New York Times since 2019. She is the United Nations bureau chief and also writes about Iranian news. Previously she was a senior writer for The Wall Street Journal for 17 years and a conflict reporter based in the Middle East. Farnaz Fassihi has been targeted by Charming Kitten with abusive purposes. | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Human Rights | Verified |
| Sector | Journalists | Verified |
| Sector | Political | Verified |
| Sector | Religious | Verified |
| Sector | Researchers | Verified |
| Region | Saudi Arabia | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
| Region | European Countries | Verified |
Extracted IOCs
- acconut-verify[.]com
- accounts-drive[.]com
- bahaius[.]info
- cpanel-services[.]site
- customers-activities[.]site
- drive-accounts[.]com
- finance-usbnc[.]info
- instagram-com[.]site
- inztaqram[.]ga
- isis-online[.]net
- leslettrespersanes[.]net
- malcolmrifkind[.]site
- niaconucil[.]org
- phonechallenges-submit[.]site
- recovery-options[.]site
- seisolarpros[.]org
- service-activity-checkup[.]site
- service-issues[.]site
- skynevvs[.]com
- software-updating-managers[.]site
- system-services[.]site
- two-step-checkup[.]site
- unirsd[.]com
- w3-schools[.]org
- yah00[.]site
- customers-service.ddns[.]net
- 3d67ce57aab4f7f917cf87c724ed7dab
- 542128ab98bda5ea139b169200a50bce
- 185[.]141.63.135
- 185[.]141.63.156
- 185[.]141.63.157
- 185[.]141.63.160
- 185[.]141.63.161
- 185[.]141.63.162
- 185[.]141.63.170
- 185[.]141.63.172
- 185[.]141.63.8
- 51[.]255.157.110
- 51[.]38.87.199
- 51[.]89.237.233
- 51[.]89.237.234
- 51[.]89.237.235
Tip: 42 related IOCs (14 IP, 26 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.
Overlaps
Source: Cyware - October 2022
Detection (one case): 3d67ce57aab4f7f917cf87c724ed7dab
Source: Mandiant - September 2022
Detection (one case): 3d67ce57aab4f7f917cf87c724ed7dab
Source: ClearSky - October 2019
Detection (four cases): 51[.]255.157.110, bahaius[.]info, customers-activities[.]site, system-services[.]site
Source: Clearsky - September 2019
Detection (18 cases): 185[.]141.63.135, 185[.]141.63.156, 185[.]141.63.157, 185[.]141.63.160, 185[.]141.63.161, 185[.]141.63.162, 185[.]141.63.172, 185[.]141.63.8, acconut-verify[.]com, drive-accounts[.]com, inztaqram[.]ga, isis-online[.]net, leslettrespersanes[.]net, niaconucil[.]org, seisolarpros[.]org, skynevvs[.]com, unirsd[.]com, w3-schools[.]org
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Charming Kitten Fake Interview Cyber Attacks
A new series of cyber attacks has been identified where hackers use deceptive emails disguised as interview requests. The attackers use these fake scenarios to direct victims to malicious websites specifically designed to steal their email login details and security codes.
The campaign is attributed to "Charming Kitten," a well-known Iranian hacking group. This group relies heavily on phishing and social engineering and maintains a close relationship with Iran’s state and Intelligence services.
The primary goal is espionage, focused heavily on stealing victims' email account credentials to map out their professional contacts and networks. Additionally, the attackers are actively developing custom malware designed to stealthily gather information from compromised Windows computers.
While the exact number of targets for their new malware remains unclear, the group's phishing activities possess an international scope. The operations span across multiple regions, targeting entities in European countries, the United States, the United Kingdom, and Saudi Arabia.
Yes, the attackers meticulously targeted journalists, political dissidents, and human rights activists. They also aimed their operations at private and government institutions, think tanks, academic institutions, and organizations affiliated with the Baha’i community.
Attackers initiated contact by impersonating a real Wall Street Journal journalist via email to build trust with their targets. Once trust was established, they provided a link hosted on Google Sites containing supposed "interview questions," which ultimately redirected victims to a fraudulent login page that captured their passwords and two-factor authentication codes.
These specific individuals and organizations possess sensitive information, valuable professional networks, and intellectual property. Accessing their private communications allows the state-backed attackers to extract intelligence that aligns with their strategic and geopolitical interests.
Individuals should be highly cautious of unexpected interview requests and verify the sender's identity through official channels before clicking links or downloading files. Organizations must monitor their systems for unauthorized changes to security settings and remain vigilant against advanced phishing pages that attempt to intercept two-factor authentication SMS codes.
This is a highly targeted and deliberate campaign. The attackers carefully select specific individuals and organizations based on their professional roles, tailoring their deceptive "interview" scenarios to match the backgrounds of the victims.