Charming Kitten, also known as Magic Hound and APT35, is an Iranian state-associated threat actor linked to the Islamic Revolutionary Guard Corps (IRGC). Other tracking names associated with its activity include Phosphorus, Mint Sandstorm, TA453, ITG18, NewsBeef, Newscaster, and Agent Serpens; these labels can cover overlapping activity sets rather than identical organizational boundaries. Its dominant mission is cyberespionage. Targets include government and defense organizations, journalists, academics, healthcare organizations, NGOs, and civil society. Documented Israeli targeting includes journalists and organizations in transportation, logistics, and technology, while broader campaigns extend across North America, Europe, and the Middle East. The actor uses spearphishing, SMS phishing, and social engineering to steal cloud-account credentials and deliver malware. Email campaigns have used shortened links leading to malicious Word documents whose macros execute PowerShell to download Pupy. SMS campaigns impersonate Google account-security notifications to harvest credentials. Its custom HYPERSCRAPE tool extracts email data from Microsoft Outlook, Gmail, and Yahoo accounts using valid credentials. Other observed malware includes PowerStar, a variant of CharmPower. Charming Kitten also scans internet-facing systems for exploitable vulnerabilities and has acquired, modified, and operationalized Log4Shell exploit code targeting CVE-2021-44228. Post-compromise activity includes stealing Active Directory domain credentials with Mimikatz, transferring tools between compromised systems through RDP, executing commands through command-line interfaces, and staging local folders in RAR archives. Its toolkit includes Havij, sqlmap, Metasploit, and Mimikatz. Base64-encoded commands and files and AES-encrypted embedded strings conceal malicious functionality and impede analysis. In addition to espionage, the actor has deployed ransomware and abused Microsoft BitLocker to encrypt victim data for ransom.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
81 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
54 malware families attributed to this actor across reporting.
49 additional families tracked in Mallory.
35 CVEs this actor has used in observed campaigns. 35 of them exploited in the wild.
Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228). Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to Log4j (CVE-2021-44228).
Charming Kitten automated exploitation of Microsoft Exchange through the ProxyShell chain: CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. Leaked logs reportedly show nationwide scanning and ASPX webshell deployment. | The article identifies CVE-2021-34473 as a component of the ProxyShell chain used to successfully or partially compromise Exchange servers.
PaperCut faced widespread exploitation in 2023 involving CVE-2023-27350, which attackers used to obtain unauthenticated administrative access and execute code.
Although they required several weeks to weaponize Log4Shell in 2022, the initial attempts to exploit CVE-2022-47966 in Zoho ManageEngine were identified on the same day the PoC was made public.
Initial Access: CVE-2024-1709 exploited to bypass auth on ScreenConnect instances at wise.edu.jo and moj.gov.jo.
30 more CVEs tied to this actor tracked in Mallory.
968 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Iranian state-sponsored threat group included for comparison because of its GitHub-based fallback command-and-control and in-memory PowerShell execution. These similarities are low-confidence overlaps and do not establish that Agent Serpens operates CL-STA-1178.
Iranian-linked group discussed as a possible—but unconfirmed—actor that could benefit from or potentially target Defense Manpower Data Center personnel data for intelligence collection and targeting.
Listed only in technique annotations. The content does not attribute ResetNightmare exploitation or a specific campaign to this group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.