Threats Feed|Charming Kitten|Last Updated 23/07/2026|AuthorCertfa Radar|Publish Date30/01/2020

Charming Kitten's Phishing Campaign Targets Global Political and Human Rights Figures

  • Actor Motivations: Espionage
  • Attack Vectors: Backdoor,Malware,Pretexting,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: Low Impact/Low Probability

Threat Overview

The Iranian hacking group Charming Kitten, closely associated with Iran's intelligence services, has launched a new series of phishing attacks targeting journalists, political activists, and human rights advocates. These attacks, consistent with the group's previous activities, also aim at private and government institutions, think tanks, academic institutions, and organizations linked to the Baha'i community in the United States, United Kingdom, Saudi Arabia, and Europe. The attackers use fake interview scenarios, impersonating journalists from prominent media outlets like the Wall Street Journal, to gain victims' trust and direct them to phishing sites. These sites capture sensitive information like passwords and two-factor authentication codes. The campaign also involves a backdoor malware named "pdfreader.exe", which alters system settings for remote access and data exfiltration.

Detected Targets

TypeDescriptionConfidence
CaseFarnaz Fassihi
Farnaz Fassihi is an Iranian-American journalist who has worked for The New York Times since 2019. She is the United Nations bureau chief and also writes about Iranian news. Previously she was a senior writer for The Wall Street Journal for 17 years and a conflict reporter based in the Middle East. Farnaz Fassihi has been targeted by Charming Kitten with abusive purposes.
Verified
SectorGovernment Agencies and Services
Verified
SectorHuman Rights
Verified
SectorJournalists
Verified
SectorPolitical
Verified
SectorReligious
Verified
SectorResearchers
Verified
RegionSaudi Arabia
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified
RegionEuropean Countries
Verified

Extracted IOCs

  • acconut-verify[.]com
  • accounts-drive[.]com
  • bahaius[.]info
  • cpanel-services[.]site
  • customers-activities[.]site
  • drive-accounts[.]com
  • finance-usbnc[.]info
  • instagram-com[.]site
  • inztaqram[.]ga
  • isis-online[.]net
  • leslettrespersanes[.]net
  • malcolmrifkind[.]site
  • niaconucil[.]org
  • phonechallenges-submit[.]site
  • recovery-options[.]site
  • seisolarpros[.]org
  • service-activity-checkup[.]site
  • service-issues[.]site
  • skynevvs[.]com
  • software-updating-managers[.]site
  • system-services[.]site
  • two-step-checkup[.]site
  • unirsd[.]com
  • w3-schools[.]org
  • yah00[.]site
  • customers-service.ddns[.]net
  • 3d67ce57aab4f7f917cf87c724ed7dab
  • 542128ab98bda5ea139b169200a50bce
  • 185[.]141.63.135
  • 185[.]141.63.156
  • 185[.]141.63.157
  • 185[.]141.63.160
  • 185[.]141.63.161
  • 185[.]141.63.162
  • 185[.]141.63.170
  • 185[.]141.63.172
  • 185[.]141.63.8
  • 51[.]255.157.110
  • 51[.]38.87.199
  • 51[.]89.237.233
  • 51[.]89.237.234
  • 51[.]89.237.235
download

Tip: 42 related IOCs (14 IP, 26 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

APT42APT42's Multi-National Cyber Operations: A Focus on Surveillance and Espionage

Source: Cyware - October 2022

Detection (one case): 3d67ce57aab4f7f917cf87c724ed7dab

APT42APT42: Uncovering the Iranian Cyber Espionage Operations and Global Targets

Source: Mandiant - September 2022

Detection (one case): 3d67ce57aab4f7f917cf87c724ed7dab

Charming KittenCharming Kitten's Expanding Cyber Campaign: Phishing for Political Influence

Source: ClearSky - October 2019

Detection (four cases): 51[.]255.157.110, bahaius[.]info, customers-activities[.]site, system-services[.]site

Charming KittenCharming Kitten Targets Researchers and Activists in Latest Espionage Campaign

Source: Clearsky - September 2019

Detection (18 cases): 185[.]141.63.135, 185[.]141.63.156, 185[.]141.63.157, 185[.]141.63.160, 185[.]141.63.161, 185[.]141.63.162, 185[.]141.63.172, 185[.]141.63.8, acconut-verify[.]com, drive-accounts[.]com, inztaqram[.]ga, isis-online[.]net, leslettrespersanes[.]net, niaconucil[.]org, seisolarpros[.]org, skynevvs[.]com, unirsd[.]com, w3-schools[.]org

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Charming Kitten Fake Interview Cyber Attacks

A new series of cyber attacks has been identified where hackers use deceptive emails disguised as interview requests. The attackers use these fake scenarios to direct victims to malicious websites specifically designed to steal their email login details and security codes.

The campaign is attributed to "Charming Kitten," a well-known Iranian hacking group. This group relies heavily on phishing and social engineering and maintains a close relationship with Iran’s state and Intelligence services.

The primary goal is espionage, focused heavily on stealing victims' email account credentials to map out their professional contacts and networks. Additionally, the attackers are actively developing custom malware designed to stealthily gather information from compromised Windows computers.

While the exact number of targets for their new malware remains unclear, the group's phishing activities possess an international scope. The operations span across multiple regions, targeting entities in European countries, the United States, the United Kingdom, and Saudi Arabia.

Yes, the attackers meticulously targeted journalists, political dissidents, and human rights activists. They also aimed their operations at private and government institutions, think tanks, academic institutions, and organizations affiliated with the Baha’i community.

Attackers initiated contact by impersonating a real Wall Street Journal journalist via email to build trust with their targets. Once trust was established, they provided a link hosted on Google Sites containing supposed "interview questions," which ultimately redirected victims to a fraudulent login page that captured their passwords and two-factor authentication codes.

These specific individuals and organizations possess sensitive information, valuable professional networks, and intellectual property. Accessing their private communications allows the state-backed attackers to extract intelligence that aligns with their strategic and geopolitical interests.

Individuals should be highly cautious of unexpected interview requests and verify the sender's identity through official channels before clicking links or downloading files. Organizations must monitor their systems for unauthorized changes to security settings and remain vigilant against advanced phishing pages that attempt to intercept two-factor authentication SMS codes.

This is a highly targeted and deliberate campaign. The attackers carefully select specific individuals and organizations based on their professional roles, tailoring their deceptive "interview" scenarios to match the backgrounds of the victims.

About Affiliation
Charming Kitten
Charming Kitten is an Iranian state-sponsored threat actor linked to the Islamic Revolutionary Guard Corps (IRGC) and active since at least 2012. The group conducts cyber espionage operations primarily targeting journalists, academics, political dissidents, think tank researchers, activists, and government officials across the Middle East, Europe, and the United States. Charming Kitten is best known for sustained credential phishing campaigns using fake login pages and social engineering, alongside the exploitation of known vulnerabilities in enterprise software. The cluster is tracked under numerous aliases across the industry including APT35, Magic Hound, Mint Sandstorm, and Phosphorus.
View Charming Kitten's Insights