Threat Actor Profile Charming Kitten

Charming Kitten, also known as APT35, Magic Hound, and Phosphorus, is a cyber-espionage group believed to be operating out of Iran. They have been active since at least 2014 and have been known to target a wide range of sectors and individuals, including biotech, energy, technology, government agencies, journalists, human rights activists, and dissidents. The threat actor has gained attention for their sophisticated and persistent cyber-espionage campaigns. What they lack in technological sophistication, they make up for with comprehensive social engineering campaigns, gaining the trust of their targets before taking over their accounts. As Charming Kitten clearly shows, sophistication comes in more than one flavour.  

The Kitten is a versatile actor, with campaigns aimed at espionage, ransomware, and even suspected kidnapping. Their modus operandi is typical of Iranian APTs, who overcome their lack of technological or financial resources by employing novel strategies. However, the threat actor has recently stepped up its game, developing custom tools and showing the ability to quickly weaponize vulnerabilities, making it an even more dangerous adversary. This APT profile should be regarded as a small peek into the world of Iranian APTs and their preferred ways of targeting their victims.

  • Aliases: Charming Kitten, APT35, Phosphorus, Ajax Security, News Beef, Magic Hound, UNC788, APT42, Parastoo, Newscaster
  • Strategic motives: Espionage, financial
  • Affiliation: Islamic Revolutionary Guard Corps (IRGC)
  • Cyber capabilities: ★★☆☆☆
  • Target sectors: Military, Government, Media, Energy, Defense Industrial Base, Engineering, Telecommunications, Dissidents
  • Observed countries: 11

Request a free membership to access our full research insights

Already a member? Login here

Origins, Motivations & Targets

Charming Kitten came into the spotlight in 2014 through a campaign on social media[5]. There are, however, signs they have been active since 2011 or 2012. In 2011, an Iranian-backed operation named Newscaster targeted US military personnel with the goal of conducting espionage.[6] In 2012, a group self-named Parastoo hacked an old server of the International Atomic Energy Agency.[7] Later, both Newscaster and Parastoo were linked to Charming Kitten due to significant overlap in their use of Tactics, Techniques and Procedures (TTPs).[8] Charming Kitten has been associated with the Iranian government and military bodies, particularly the Islamic Revolutionary Guard Corps (IRGC). The APT’s goals often align with those of the IRGC, as has been recognized by the US government as well. Since 2020, parts of the cyber-branch of the IRGC have been sanctioned by the US Department of Treasury, including individuals who are linked to Charming Kitten.[9]

Not uncommon for APTs, Charming Kitten seems to have a taste for targeting individuals, through whom access to an organization or sensitive information is obtained. Extensive, complex spear-phishing and social engineering operations comprise an important part of their modus operandi. Charming Kitten often reaches out to military personnel, diplomats, and other government officials through social media in attempts to establish trusted relationships with their targets. Journalists, (academic) researchers and dissidents abroad have also been targeted by the group. Their victims are often selected based on their line of work or political stance towards the Iranian regime.[10] Most operations targeted people abroad, but a few instances of domestic espionage have also been noted.[11]

Since 2021, the group has evolved beyond relying solely on their ability to mislead and deceive, although this remains their specialty. In the last few years, new skills and custom developed tools have been added to their toolbox, making them more dangerous than they have ever been. The scope of their targeting has also broadened, including much more high-value targets, such as critical infrastructure and international organizations. For this reason, Hunt & Hackett closely tracks the group in order to stay ahead. 

SWOT analysis

Strengths, weaknesses, opportunities & threats

Strengths

  • IRGC backing
  • Social Engineering and spear-phishing capabilities
  • No fear from criminal prosecution
  • Steep learning curve present in recent years

Weaknesses

  • Unable to find zero-days (so far), making use only of N-days
  • Low success rate for their known campaigns
  • Unable to conduct long-term espionage activities

Opportunities

  • Increasing priority for the IRGC
  • Continuing to develop new tools and tactics
  • Attracting more specialized personnel

Threats

  • Increased attention on Iranian activity in general
  • Further worsening of the Iranian economy due to international sanctions

Campaigns Overview

January 1, 2022
16:00 PM

Newscaster & Parastoo, the predecessors

2011-2014

From 2011 to 2014, Charming Kitten's predecessors, Newscaster and Parastoo, emerged. Newscaster employed creative hacking techniques to overcome technical limitations, impacting over 2.000 individuals and aiming to steal credentials. They established friendly relations with targets on social media platforms and deceived them into clicking malicious links.[12] High-ranking military and government personnel from countries like the US, Israel, Britain, and Saudi Arabia were targeted, potentially compromising sensitive information. The full extent of the data breach remains unclear.[13] 

Parastoo gained attention when an old IAEA server was hacked. The stolen loot comprised non-sensitive and publicly available data, and the operation displayed a lack of sophistication as it relied on exploiting a much older known vulnerability.[14] In 2014, after FireEye produced a report unravelling the operations of Charming Kitten, its existing infrastructure was dismantled, and the group went dormant for a few years.[15]

January 1, 2022
16:00 PM

HBO hacked, Game of Thrones script stolen

2017

Charming Kitten made headlines again in 2017, when an Iranian hacker named Behzad Mesri breached HBO's servers and obtained scripts for multiple TV shows, including a yet-to-be-released episode of the chart-topping Game of Thrones series. Mesri demanded a payment of $6 million in Bitcoin to prevent the release of the stolen scripts. While ClearSky, an Israeli cybersecurity company, suspected Mesri was a former member of Charming Kitten, it is believed that the HBO hack was likely a financially motivated individual act, rather than an operation conducted directly by Charming Kitten.[16]

Mesri could be linked to the dormant APT as he used infrastructure previously employed by Charming Kitten. Withstanding the threats from the hacker, HBO stood its ground and did not pay the ransom. The damage the company suffered through the leaks of stolen data was mild, and HBO’s crisis response approach was praised by experts.[17]

January 1, 2022
16:00 PM

US elections interference

2019

In 2019, Charming Kitten resurfaced, and according to a ClearSky report, they were reportedly targeting the re-election campaign of US President Trump.[18] In the attack, the threat actor displayed a number of new social engineering tactics, among others impersonating the security team of social media platforms.[19] The motive behind this targeting could be linked to President Trump's strong opposition to the Iran Nuclear Deal. A Microsoft report detailing the attacks said the accounts were attacked using a considerable amount of personal information of the targets, characteristic for the Kittens.[20]

January 1, 2022
16:00 PM

From cyber to kinetic operations?

2021

Although Charming Kitten primarily focuses on intelligence gathering, there have been recent connections to more aggressive actions. In 2021 and 2022, the Israeli intelligence service Shin Bet uncovered evidence of the IRGC employing phishing techniques in support of kidnapping operations. By cross-referencing indicators from the Shin Bet report with their own intelligence, cybersecurity firm Proofpoint assessed with moderate confidence that Charming Kitten was likely responsible for the phishing attempt.[21]

Proofpoint conducted another investigation involving a murder-for-hire plot orchestrated by the IRGC in the US. One of the targeted individuals had their system infected with the Korg malware, which is known to be exclusively used by Charming Kitten. This finding further solidifies the strong correlation between Charming Kitten's activities and the operations of the IRGC.[22]

January 1, 2022
16:00 PM

"We do Ransomware now"

2021

The shapeshifting Charming Kitten took yet another turn in 2021, this time towards ransomware. Microsoft noticed that the group was scanning millions of IPs worldwide in order to see if they could still exploit the older vulnerability CVE-2018-13379 and deploy ransomware on the targeted systems. Of the hundreds of systems that they found were possible to infiltrate, they selected a handful to access through social engineering methods. Again, as will become apparent in several examples on this page, the attackers tricked the target into handing over their credentials. Microsoft attributed at least two ransomware campaigns to Charming Kitten in 2021.[23]

January 1, 2022
16:00 PM

A new level of sophistication

2023

The Charming Kittens today have evolved further and are becoming increasingly sophisticated. Microsoft’s threat intelligence team noted that a subgroup is operationally mature and capable of developing custom tools and quickly exploiting new vulnerabilities. Previously, the Kittens were slow in adopting exploits for vulnerabilities with publicly available proof-of-concepts (POCs), taking weeks to weaponize exploits like Proxyshell and Log4Shell. However, since early 2023 a notable decrease is observable in the time it takes for them to adopt and incorporate public POCs. In this 2023 campaign, the group targeted energy companies, seaports and other critical infrastructure in the US, likely as retaliation for cyberattacks in Iran that were blamed on the US and Israel. These targets are yet again a broadening of the scope of Charming Kitten and prove that the group is becoming increasingly relevant.[24] However, it is worth noting that the new levels of sophistication currently seen in the operation of the group is not entirely new founded. A new backdoor - nicknamed as Sponsor by ESET researchers – which was discovered in 2023, was found to have been used against at least 34 victims in Brazil, Israel and the UAE dating back as early as March 2021.[25]

More detailed information about this actor?

Already a member? Login here

Charming Kitten in the Netherlands

There is no account yet of Charming Kitten being active in the Netherlands. However, Iranian actors have set their sights on the Netherlands in the past, and due to the increasing versatility of Charming Kitten, it is possible that an attack will occur eventually. Iranian actors are nothing new in the Netherlands, as they were responsible for one of the country's most notorious hacks, at DigiNotar.[48] Also, in 2020, PwC published a report saying that Iranian hackers had tried to compromise Dutch universities and colleges, seeking to obtain knowledge to use in their own educational system.[49]

Due to Charming Kitten’s recent step-up in sophistication, and in addition to the change in motivation (retaliation attack in 2023 and targeting critical infrastructure), the group forms a realistic threat to organizations in the Netherlands. The General Intelligence & Security Agency (AIVD) has been issuing warnings for years about Iran’s offensive activities in Dutch cyberspace, describing it as one of the biggest digital threats to the Netherlands.[50]

 

Country distribution of IoCs based on IPs(1)

Figure 5 – The Netherlands is the second most used IP address supplier for Charming Kitten’s attacks 

 

Another angle where the Netherlands shows up when looking into Charming Kitten, is that they often make use of Dutch IPs for their attacks. In an investigation into Indicators of Compromise (IoC) of the threat actor, IP addresses from the Netherlands were featured prominently. After the US, the Netherlands is the second most used country for IP addresses (see Figure 5).[51] A plausible reason for this is the high-quality ICT infrastructure in the Netherlands, which is reliable, stable and accessible.[52]

Trends

For years, Charming Kitten was best known for their extensive spear-phishing and social engineering campaigns. With tricks and persistence, they were able to breach the email accounts of their targets. This remains a core component of their approach to breaching targets to this day. However, since 2021 there are a few clear changes in the way the Kittens operate, and the targets they choose. From attacking dissidents and scholars, they have expanded their activities to ransomware attacks and attacking critical infrastructure. This new range of targeting was accompanied by the development of custom tools, such as BELLACIAO and HYPERSCRAPER, and they gained ability to quickly weaponize known vulnerabilities (N-days), sometimes within the first day of going public.  

This trend coincided with a simultaneous decrease in ransomware and wiper attacks from threat actors associated with the IRGC, indicating that after a few forays into financial and sabotage-motivated attacks, Charming Kitten returned to the espionage track. The shift in tactics also aligns with faster adoption of newly reported vulnerabilities, the use of compromised websites for command and control (C2) purposes to obscure the source of attacks, and in some cases, the development of customized tools and advanced techniques. These developments collectively indicate that although Iranian threat groups may not possess the same level of technical sophistication as their Russian and Chinese counterparts, they are improving their ability to gain access to specific targets of interest, maintain persistence, and evade detection.[53]

Their rapid development implies that Charming Kitten is benefitting from the uptick in priority that the IRGC has been receiving from Tehran; the IRGC is pocketing larger portions of Iran’s state budget every year, at the cost of the traditional military. For example, in 2023, the IRGC received 31% of the military budget, compared to the 11% that went to the army.[54] Through these statistics, Tehran’s priorities are becoming clear, especially when considering that the army employs 2.5 times more personnel than the IRGC.[55] With the new funds, the IRGC is able to modernize its operations and equipment. The increasing priority for the IRGC is indicating that Iran is stepping up its irregular warfare capabilities and focusing less on traditional military forces. With the IRGC as its omnipotent tool, Iran hopes to establish regional power, and counter its stronger adversaries globally, like the US.[56]

The advancement of the group is worrying, as their activities become harder to predict. Who knows when they will resort to ransomware again? Or focus all their attention on developing new tools? Over the timeframe 2021-2023, Charming Kitten has shown a great versatility in modus operandi, targeting, and motivation. With their expanding activities and their overarching benefactor’s growing funds, the future of the group remains shrouded in mystery. 

Conclusions & Future Implications

In conclusion, Charming Kitten is a remarkably versatile threat actor, associated with the Iranian Islamic Revolutionary Guard Corps. What started with cracking open old servers a decade ago gradually evolved into ransomware attacks, which in turn evolved into targeting high-value critical infrastructure. Their targets are global, but are mostly based in the Middle East, the US, and Europe. The individuals and organizations that have their attention are from a wide range of professions and expertise, but include academics, energy, technology, and aerospace.  

Moving beyond relying heavily on their ability to trick their victims with extensive social engineering, the group now progressively develops its own tools and adds layers of sophistication at a high pace. These are worrying developments, as Charming Kitten is learning quickly and becomes more and more sophisticated in technical terms. Their jumpy evolution and versatility is what makes them unpredictable and dangerous. Agile defenses are needed to counter their next move. 

Considering that the IRGC is only increasing in importance to the regime in Teheran, it is likely that Charming Kitten will benefit from this as well. More resources are being dedicated to the IRGC, and this provides opportunities for their hacking teams to attract competent staff, develop new tools and techniques, becoming more and more sophisticated. More likely than not, the world has yet to meet the full extent of Charming Kitten’s power. 

Sint oratio at per, diam saepe dicam ei sea. At civibus appetere cum, quem habeo in. Eam modo apeirian te, ut altera iisque evertitur sit. Cu saperet inermis aliquando nam, per impetus qualisque interesset ex, vix at omittantur instructior disputationi.

Sources

 

  1. https://www.recordedfuture.com/social-engineering-remains-key-tradecraft-for-iranian-apts
  2. https://www.mei.edu/publications/iranian-apts-overview
  3. https://www.clearskysec.com/wp-content/uploads/2017/12/Charming_Kitten_2017.pdf
  4. https://www.youtube.com/watch?v=7LFtSFIZw7k
  5. https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2014/2014.05.28.NewsCaster_An_Iranian_Threat_Within_Social_Networks/file-2581720763-pdf.pdf
  6. https://cyware.com/news/everything-you-need-to-know-about-operation-newscaster-bb523b3e
  7. https://www.yalescientific.org/2013/02/agency-attacked-parastoo-hacks-the-iaea/
  8. https://unit42.paloaltonetworks.com/threat-brief-iranian-linked-cyber-operations/
  9. https://home.treasury.gov/news/press-releases/jy0948
  10. https://explore.avertium.com/resource/in-depth-look-at-apt35-aka-charming-kitten
  11. https://blog.sekoia.io/iran-cyber-threat-overview/
  12. https://cyware.com/resources/research-and-analysis/ten-years-top-charming-kittens-tale-of-cybercrime-ea43
  13. https://www.washingtontimes.com/news/2014/may/29/iranian-hackers-sucker-punch-us-defense-heads-crea/
  14. https://www.thedailybeast.com/did-irans-cyber-army-hack-into-the-iaeas-computers
  15. https://www.bleepingcomputer.com/news/security/hbo-hacker-was-part-of-irans-charming-kitten-elite-cyber-espionage-unit/
  16. https://www.welivesecurity.com/en/eset-research/sponsor-batch-filed-whiskers-ballistic-bobcats-scan-strike-backdoor/
  17. https://www.theguardian.com/media/2017/aug/25/hbo-game-of-thrones-hack-ransom-future-cyber-risks#:~:text=The%20Time%20Warner%2Downed%20company,finale%20as%20planned%20this%20Sunday
  18. https://www.clearskysec.com/wp-content/uploads/2019/10/The-Kittens-Are-Back-in-Town-2.pdf
  19. https://threatpost.com/iran-linked-charming-kitten-touts-new-spearphishing-tactics/149109/
  20. https://blogs.microsoft.com/on-the-issues/2019/10/04/recent-cyberattacks-require-us-all-to-be-vigilant/
  21. https://www.proofpoint.com/uk/blog/threat-insight/ta453-refuses-be-bound-expectations
  22. https://www.justice.gov/opa/pr/member-irans-islamic-revolutionary-guard-corps-irgc-charged-plot-murder-former-national
  23. https://www.microsoft.com/en-us/security/blog/2021/11/16/evolving-trends-in-iranian-threat-actor-activity-mstic-presentation-at-cyberwarcon-2021/
  24. https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
  25. https://www.welivesecurity.com/en/eset-research/sponsor-batch-filed-whiskers-ballistic-bobcats-scan-strike-backdoor/
  26. https://attack.mitre.org/groups/G0059/
  27. https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit/
  28. https://attack.mitre.org/techniques/T1204/
  29. https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting/
  30. https://thedfirreport.com/2022/03/21/phosphorus-automates-initial-access-using-proxyshell/
  31. https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/
  32. https://thedfirreport.com/2022/03/21/phosphorus-automates-initial-access-using-proxyshell/
  33. https://unit42.paloaltonetworks.com/unit42-magic-hound-campaign-attacks-saudi-targets/
  34. https://www.comparitech.com/blog/information-security/credential-dumping/
  35. https://unit42.paloaltonetworks.com/unit42-magic-hound-campaign-attacks-saudi-targets/
  36. https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/
  37. https://blog.certfa.com/posts/charming-kitten-christmas-gift/
  38. https://www.volexity.com/blog/2024/02/13/charmingcypress-innovating-persistence/
  39. https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting/
  40. https://explore.avertium.com/resource/in-depth-look-at-apt35-aka-charming-kitten
  41. https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool/
  42. https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
  43. www.itsecurityguru.org/2023/04/28/charming-kitten-using-new-malware-in-multi-country-attacks/
  44. https://therecord.media/iran-apt-charming-kitten-bellaciao-malware-us-europe-asia
  45. https://www.youtube.com/watch?v=7LFtSFIZw7k
  46. https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
  47. https://www.blackhatethicalhacking.com/news/basicstar-charming-kittens-latest-cyberweapon/
  48. https://www.nu.nl/internet/2961331/zwaar-verouderde-website-was-oorzaak-diginotar-hack.html
  49. https://nos.nl/artikel/2322945-iraanse-overheidshackers-vallen-nederlandse-onderwijsinstellingen-aan
  50. https://www.aivd.nl/onderwerpen/jaarverslagen/jaarverslag-2022/internationale-dreigingen
  51. https://circleid.com/posts/20201218-a-brief-osint-analysis-of-charming-kitten-iocs
  52. https://www.aivd.nl/onderwerpen/jaarverslagen/jaarverslag-2022/internationale-dreigingen
  53. https://cyberscoop.com/iranian-information-operations-hacking-microsoft-report/
  54. https://epc.ae/en/details/featured/iran-s-new-year-military-budget-and-shifting-priorities
  55. https://www.rferl.org/a/persian-might-a-look-at-tehran-s-military-capability-amid-the-u-s--iranian-conflict/30368967.html
  56. https://www.cfr.org/backgrounder/irans-revolutionary-guards 

Learn more about our threat research?

Get in touch