Charming Kitten is an Iranian cyber-espionage threat actor widely associated with APT35 and linked in reporting to Unit 1500 of the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). The group is known for intelligence collection operations aligned with Iranian state interests. Reporting has tied the actor to operational infrastructure procurement and registration activity that used the address of a real Dutch bakery as cover, illustrating the use of spoofed or deceptive registration details to support operations. Charming Kitten is best characterized as a state-aligned espionage actor rather than a financially motivated cybercriminal group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked espionage actor described as using a real Dutch bakery address as cover/false registration details when procuring infrastructure (servers/domains), consistent with operational security and attribution-evasion tradecraft.
Iranian cyber-espionage group; subject of repeated data leaks exposing tooling, operations, and alleged members/front companies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.