Charming Kitten is an Iran-based threat actor associated with cyber espionage activity and widely tracked under aliases including Yellow Garuda, PHOSPHORUS, and ITG18. The group is known for persistent targeting of victims worldwide and for campaigns that combine social engineering with phishing, compromise of legitimate websites, mobile malware deployment, and the use of Telegram bots to fingerprint victim devices. Its operations span from relatively simple credential-harvesting activity to more involved intrusion tradecraft oriented toward victim profiling and follow-on compromise. The actor is assessed to be state-aligned and primarily motivated by espionage. Charming Kitten is notable for sustained use of deceptive lures and social engineering to obtain access, as well as collection-focused activity consistent with intelligence requirements.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.