Back to ThreatBox
ThreatBox · Threat Actor Attribution

Charming Kitten

a.k.a. APT35, Phosphorus, Mint Sandstorm, TA453, Ballistic Bobcat
Espionage (state-sponsored) Iran (IRGC — Islamic Revolutionary Guard Corps) First seen 2013

Charming Kitten is the IRGC's premier cyber-espionage arm, focused on Iran-diaspora surveillance, journalist targeting, and nuclear-policy intelligence. Known for long-form, patient social-engineering (fake journalist personas, months-long chat rapport before payload delivery), MFA-phishing kits, and abuse of legitimate cloud services (Dropbox, Google Drive) for C2. Sub-cluster HomeLand Justice runs destructive operations against Albania and Israel.

Targeted sectors
JournalistsHuman rights activistsAcademiaGovernment policyNuclear research
Targeted regions
USAUKIsraelMiddle East

Known TTPs (3)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2019-10
    Attempted breach of a US presidential campaign (Microsoft disclosure)
  2. 2022-07
    Albania government destructive attack (HomeLand Justice)
  3. 2023-05
    PowerLess & POWERSTAR backdoor campaigns against Israeli/Western researchers

References

End of dossier · Charming Kitten
Back to ThreatBox