ThreatBox · Threat Actor Attribution
Charming Kitten
a.k.a. APT35, Phosphorus, Mint Sandstorm, TA453, Ballistic Bobcat
Espionage (state-sponsored) Iran (IRGC — Islamic Revolutionary Guard Corps) First seen 2013
Charming Kitten is the IRGC's premier cyber-espionage arm, focused on Iran-diaspora surveillance, journalist targeting, and nuclear-policy intelligence. Known for long-form, patient social-engineering (fake journalist personas, months-long chat rapport before payload delivery), MFA-phishing kits, and abuse of legitimate cloud services (Dropbox, Google Drive) for C2. Sub-cluster HomeLand Justice runs destructive operations against Albania and Israel.
Targeted sectors
JournalistsHuman rights activistsAcademiaGovernment policyNuclear research
Targeted regions
USAUKIsraelMiddle East
Known TTPs (3)
T1566.003Spearphishing via Service (fake journalist personas)
T1102Web Service
T1621MFA Bypass (Evilginx-style)
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2019-10Attempted breach of a US presidential campaign (Microsoft disclosure)
- 2022-07Albania government destructive attack (HomeLand Justice)
- 2023-05PowerLess & POWERSTAR backdoor campaigns against Israeli/Western researchers
References
End of dossier · Charming Kitten
Back to ThreatBox