Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign
- Actor Motivations: Espionage
- Attack Vectors: Spear Phishing
- Attack Complexity: Medium
- Threat Risk: Low Impact/Low Probability
Threat Overview
The Iranian APT group Charming Kitten (APT35) conducted a cyberespionage campaign targeting academic researchers, human rights activists, media personnel, and public figures across the Middle East, US, UK, and France. Using spearphishing emails and fake websites mimicking Google and Instagram, the group sought to steal credentials and track email activity. They also impersonated journalists and researchers to deceive victims into sharing sensitive information. Key targets included Iranian dissidents, non-Iranian researchers focused on Iran, and influential public figures. The campaign employed social engineering, custom infrastructure, and domain impersonation, leveraging hosting services in Bulgaria and Germany. Notable tactics included phishing for credentials and redirecting victims to decoy domains.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Dissident | Verified |
| Sector | Human Rights | Verified |
| Sector | Researchers | Verified |
| Region | France | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
| Region | Middle East Countries | Verified |
Extracted IOCs
- acconut-verify[.]com
- deutcshewelle[.]net
- drive-accounts[.]com
- exnovin[.]org
- inztaqram[.]ga
- isis-online[.]net
- islamicemojimaker[.]com
- jewishjournal[.]online
- leslettrespersanes[.]net
- niaconucil[.]org
- seisolarpros[.]org
- skynevvs[.]com
- unirsd[.]com
- unrisd[.]com
- w3-schools[.]org
- accounts-drive.comw3-schools[.]org
- google.drive-accounts[.]com
- 185[.]141.63.135
- 185[.]141.63.156
- 185[.]141.63.157
- 185[.]141.63.160
- 185[.]141.63.161
- 185[.]141.63.162
- 185[.]141.63.172
- 185[.]141.63.8
- 46[.]21.150.197
Tip: 26 related IOCs (9 IP, 17 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: Certfa - January 2020
Detection (18 cases): 185[.]141.63.135, 185[.]141.63.156, 185[.]141.63.157, 185[.]141.63.160, 185[.]141.63.161, 185[.]141.63.162, 185[.]141.63.172, 185[.]141.63.8, acconut-verify[.]com, drive-accounts[.]com, inztaqram[.]ga, isis-online[.]net, leslettrespersanes[.]net, niaconucil[.]org, seisolarpros[.]org, skynevvs[.]com, unirsd[.]com, w3-schools[.]org
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Charming Kitten Cyberespionage Campaign
An Iranian cyberespionage campaign was detected using fraudulent emails and fake websites to deceive individuals into sharing their account login credentials. The attackers impersonated well-known news outlets, academic institutes, and media personalities to gain trust and deploy web trackers to gather location and system data from victims.
The campaign was carried out by Charming Kitten (also known as APT35, Phosphorus, or Ajax), an Iranian cyberespionage group active since at least 2014. The group is known for targeting human rights activists, journalists, academics, and foreign experts on Iranian affairs using deceptive email campaigns and look-alike login portals.
The primary goal of the attack was long-term intelligence gathering and credentials theft. The threat actors targeted academic researchers, journalists, media personnel, public figures, and political dissidents in the US, the UK, France, and the Middle East who focus on Iranian issues.
The attackers sent convincing emails offering online meeting invitations or CV reviews while posing as reputable journalists or institutions. Clicking the provided links led victims to fake login pages designed to steal passwords for services like Gmail, Google Drive, and Instagram, or silently installed a tracking cookie to monitor the victim's location and email sharing.
This was a highly targeted cyberespionage operation directed at specific high-value individuals, institutions, and experts rather than a broad attack on the general public.
Individuals and organizations should enable multi-factor authentication on all online accounts, inspect website URLs carefully before entering login credentials, avoid clicking links in unexpected emails, and report suspicious contact attempts from unfamiliar entities.