Threats Feed|Charming Kitten|Last Updated 23/07/2026|AuthorCertfa Radar|Publish Date15/09/2019

Charming Kitten Targets Researchers and Activists in Latest Espionage Campaign

  • Actor Motivations: Espionage
  • Attack Vectors: Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: Low Impact/Low Probability

Threat Overview

The Iranian APT group Charming Kitten (APT35) conducted a cyberespionage campaign targeting academic researchers, human rights activists, media personnel, and public figures across the Middle East, US, UK, and France. Using spearphishing emails and fake websites mimicking Google and Instagram, the group sought to steal credentials and track email activity. They also impersonated journalists and researchers to deceive victims into sharing sensitive information. Key targets included Iranian dissidents, non-Iranian researchers focused on Iran, and influential public figures. The campaign employed social engineering, custom infrastructure, and domain impersonation, leveraging hosting services in Bulgaria and Germany. Notable tactics included phishing for credentials and redirecting victims to decoy domains.

Detected Targets

TypeDescriptionConfidence
SectorDissident
Verified
SectorHuman Rights
Verified
SectorResearchers
Verified
RegionFrance
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • acconut-verify[.]com
  • deutcshewelle[.]net
  • drive-accounts[.]com
  • exnovin[.]org
  • inztaqram[.]ga
  • isis-online[.]net
  • islamicemojimaker[.]com
  • jewishjournal[.]online
  • leslettrespersanes[.]net
  • niaconucil[.]org
  • seisolarpros[.]org
  • skynevvs[.]com
  • unirsd[.]com
  • unrisd[.]com
  • w3-schools[.]org
  • accounts-drive.comw3-schools[.]org
  • google.drive-accounts[.]com
  • 185[.]141.63.135
  • 185[.]141.63.156
  • 185[.]141.63.157
  • 185[.]141.63.160
  • 185[.]141.63.161
  • 185[.]141.63.162
  • 185[.]141.63.172
  • 185[.]141.63.8
  • 46[.]21.150.197
download

Tip: 26 related IOCs (9 IP, 17 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

Charming KittenCharming Kitten's Phishing Campaign Targets Global Political and Human Rights Figures

Source: Certfa - January 2020

Detection (18 cases): 185[.]141.63.135, 185[.]141.63.156, 185[.]141.63.157, 185[.]141.63.160, 185[.]141.63.161, 185[.]141.63.162, 185[.]141.63.172, 185[.]141.63.8, acconut-verify[.]com, drive-accounts[.]com, inztaqram[.]ga, isis-online[.]net, leslettrespersanes[.]net, niaconucil[.]org, seisolarpros[.]org, skynevvs[.]com, unirsd[.]com, w3-schools[.]org

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Charming Kitten Cyberespionage Campaign

An Iranian cyberespionage campaign was detected using fraudulent emails and fake websites to deceive individuals into sharing their account login credentials. The attackers impersonated well-known news outlets, academic institutes, and media personalities to gain trust and deploy web trackers to gather location and system data from victims.

The campaign was carried out by Charming Kitten (also known as APT35, Phosphorus, or Ajax), an Iranian cyberespionage group active since at least 2014. The group is known for targeting human rights activists, journalists, academics, and foreign experts on Iranian affairs using deceptive email campaigns and look-alike login portals.

The primary goal of the attack was long-term intelligence gathering and credentials theft. The threat actors targeted academic researchers, journalists, media personnel, public figures, and political dissidents in the US, the UK, France, and the Middle East who focus on Iranian issues.

The attackers sent convincing emails offering online meeting invitations or CV reviews while posing as reputable journalists or institutions. Clicking the provided links led victims to fake login pages designed to steal passwords for services like Gmail, Google Drive, and Instagram, or silently installed a tracking cookie to monitor the victim's location and email sharing.

This was a highly targeted cyberespionage operation directed at specific high-value individuals, institutions, and experts rather than a broad attack on the general public.

Individuals and organizations should enable multi-factor authentication on all online accounts, inspect website URLs carefully before entering login credentials, avoid clicking links in unexpected emails, and report suspicious contact attempts from unfamiliar entities.

About Affiliation
Charming Kitten
Charming Kitten is an Iranian state-sponsored threat actor linked to the Islamic Revolutionary Guard Corps (IRGC) and active since at least 2012. The group conducts cyber espionage operations primarily targeting journalists, academics, political dissidents, think tank researchers, activists, and government officials across the Middle East, Europe, and the United States. Charming Kitten is best known for sustained credential phishing campaigns using fake login pages and social engineering, alongside the exploitation of known vulnerabilities in enterprise software. The cluster is tracked under numerous aliases across the industry including APT35, Magic Hound, Mint Sandstorm, and Phosphorus.
View Charming Kitten's Insights