APT35 is an Iran-linked cyber-espionage threat actor active since at least 2011 and associated with long-running surveillance and credential-harvesting operations against individuals and organizations of intelligence interest. The cluster is widely tracked under multiple aliases including COBALT ILLUSION, Charming Kitten, PHOSPHORUS, TA453, APT42, Magic Hound, Newscaster, NewsBeef, UNC788, ITG18, Yellow Garuda, CharmingCypress, and as a subgroup in some vendor taxonomies such as Mint Sandstorm. Reporting has also linked elements of this activity to Behzad Mesri, who was indicted by the FBI in 2019 and described as acting on behalf of the Islamic Revolutionary Guard Corps. The actor is assessed to operate on behalf of Iran with espionage as its dominant mission, focusing on surveillance of persons of interest and collection of credentials and other sensitive information. Its targeting spans a broad range of individuals and industry verticals rather than a single sector, and its operations commonly rely on social engineering tailored to specific victims. APT35 is known for extensive use of fake social media personas, phishing campaigns, and strategic web compromises. It has spoofed common webmail brands such as Gmail and Yahoo, used shortened links to obscure phishing infrastructure, and personalized phishing pages with victim-specific details such as names and images to increase credibility. The group has also run themed lure operations, including news media and recruitment pretexts, and has used both fake websites and compromised legitimate sites to deliver lures and tooling. In post-compromise activity, the actor has deployed tools including BeEF and PupyRAT. Operational security failures have periodically exposed phishing kits and targeting databases, providing insight into victim selection and workflow. The activity is often described as involving loosely connected operators or contractors whose varying tradecraft and possible side operations complicate attribution and create overlap with adjacent Iran-aligned clusters.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster referenced as exploiting/associated with exploitation of FortiOS/FortiGate CVE-2020-12812 (2FA bypass).
COBALT ILLUSION is known for conducting espionage and surveillance operations on behalf of Iran, targeting individuals and organizations using phishing, fake social media personas, and strategic web compromise. They use open source tools and have been active since at least 2011.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.