HYPERSCRAPE, also known as EmailDownloader, is a custom email data-theft tool associated with the Iranian state-linked espionage actor APT35, commonly known as Charming Kitten. It accesses compromised Gmail, Yahoo, and Microsoft Outlook accounts using valid credentials and extracts email data for espionage. Its use has also been attributed to activity tracked as COBALT ILLUSION.
HYPERSCRAPE is designed to run locally and requires a response from command-and-control infrastructure before proceeding. It serves as a post-compromise collection and exfiltration tool rather than an initial-access mechanism: operators use existing account access to retrieve victim communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT35 has previously used its own custom tool, HYPERSCRAPE, to extract data from Microsoft Outlook accounts, Gmail, and Yahoo using valid credentials.
In December 2021, the Google Threat Analysis Group (TAG) reported on COBALT ILLUSION's use of the custom HYPERSCRAPE (also known as EmailDownloader) tool to steal user data from Gmail, Yahoo, and Microsoft accounts.
The use of Google Takeout to extract data from a compromised account is in line with the features of the HYPERSCRAPE tool identified by the Google TAG team, although Human Rights Watch could not confirm if the tool was used based on logs to which it had access.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Hyperscrape, used to quietly extract emails from Yahoo!, Google, and Microsoft Outlook mailboxes once valid credentials or session cookies are obtained.
APT35 developed a tool called Hyperscrape designed to log in and silently exfiltrate emails from victim Gmail and Microsoft accounts.
In at least one case, the attacker synced the target’s mailbox and performed a Google Takeout, a service that exports all of an account’s activity and information including web searches, payments, travel and locations, ads clicked on, YouTube activity, and additional account information.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A data extraction tool attributed in the referenced reporting to APT35/Charming Kitten. It runs locally but requires a response from one of two C2 servers before proceeding.
A custom tool used by COBALT ILLUSION to steal user data from Gmail, Yahoo, and Microsoft accounts after account compromise.
A custom APT35 tool used to authenticate to victim Gmail/Microsoft accounts and silently exfiltrate email data.
A data-exfiltration tool used to log into victim Gmail and Microsoft accounts and silently steal emails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.