APT35 is an Iranian state-linked cyber espionage threat actor widely tracked under aliases including Magic Hound, Charming Kitten, Phosphorus, Mint Sandstorm, Crimson Sandstorm, TA453, TA455, TA456, Cobalt Illusion, Cobalt Mirage, Newscaster, NewsBeef, Imperial Kitten, Smoke Sandstorm, Cuboid Sandstorm, Bohrium, Calanque, ITG18, UNC1549, and Agent Serpens. The actor has been associated with operations aligned with Iranian strategic interests and is commonly assessed as conducting espionage-focused intrusions, credential collection, surveillance, and follow-on access operations against governments, civil society, media, and regional and international targets. APT35 is known for targeted phishing and spearphishing, including personalized malicious attachments and fraudulent infrastructure crafted to impersonate trusted brands or services. The group has repeatedly used malicious documents, scripts, and PowerShell-based execution chains to gain initial access and deliver additional payloads. Post-compromise activity includes downloading secondary tools, command execution, host profiling, process discovery, user and system information collection, and network configuration discovery. Observed malware capabilities include enumerating running processes, collecting usernames, gathering host architecture and operating system details, identifying local and external network information, listing drives and directories, and taking screenshots for operator visibility. The actor has also demonstrated persistence and stealth techniques, including Registry Run key persistence and hidden execution of dropped components or PowerShell activity. Custom malware associated with the group has supported screenshot capture, keylogging, and command-and-control tasking. Reported tooling and procedures show a strong emphasis on victim reconnaissance, credential and information theft, and maintaining durable access to compromised environments. APT35 overlaps in public reporting with broader Iranian intrusion activity and has at times been discussed alongside or confused with other Iranian clusters, but it remains most consistently recognized as a distinct Iranian espionage actor. Its operations have targeted victims in the United States, Israel, the United Kingdom, the Gulf region, Turkey, Jordan, Pakistan, and other countries across Europe, the Middle East, and Asia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
61 malware families attributed to this actor across reporting.
56 additional families tracked in Mallory.
32 CVEs this actor has used in observed campaigns. 32 of them exploited in the wild.
In this incident, COBALT MIRAGE exploited the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207). | In this incident, COBALT MIRAGE exploited the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207). Although the ProxyShell vulnerabilities were disclosed in August 2021, COBALT MIRAGE continues to have success exploiting them to compromise organizations.
In addition to the windows FRPC variants, ELF variants were identified that were also used with log4j exploitation. ... The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities.
Although they required several weeks to weaponize Log4Shell in 2022, the initial attempts to exploit CVE-2022-47966 in Zoho ManageEngine were identified on the same day the PoC was made public.
In this incident, COBALT MIRAGE exploited the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207).
Apache Log4j2 (aka Log4Shell) (CVE-2021-44228 and CVE-2021-45046)... Microsoft’s guidance for organizations using applications vulnerable to Log4Shell exploitation can be found here.
27 more CVEs tied to this actor tracked in Mallory.
853 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian-linked espionage threat group analyzed through a multi-stage malware infection chain using a malicious .LNK shortcut, PDF decoy, malicious DLLs, layered decryption, and the PowerLess component for follow-on malicious activity including data theft.
Suspected Iran-linked threat actor conducting recruitment-themed intrusion activity and abusing compromised supplier/partner accounts to access aerospace and defense targets.
Referenced as likely using AI-assisted development to build a new backdoor, illustrating the article’s broader point about AI lowering barriers for offensive cyber capability.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.