Charming Kitten is an Iranian state-sponsored cyber espionage threat actor active since at least 2014 and widely associated with the Islamic Revolutionary Guard Corps (IRGC). The group is commonly tracked under multiple aliases including APT35, Phosphorus, Ajax, NewsBeef, TA453, Yellow Garuda, ITG18, UNC788, and in some reporting APT42. It is known for persistent intelligence collection against individuals and organizations of strategic interest to Iran, including academics, researchers, journalists, human rights activists, dissidents, members of minority communities, government officials, diplomatic personnel, medical and public health organizations, and policy experts in the United States, Israel, Europe, and the Middle East. The actor is best known for highly tailored social-engineering operations centered on credential theft and account compromise. Its campaigns frequently use spear-phishing, impersonation of journalists or researchers, fake event invitations, and long-running rapport-building over email and social platforms. Public reporting has also documented the group using messaging applications and professional networking platforms to cultivate targets, reinforce pretexts, and pressure victims into visiting phishing pages or surrendering credentials, including multi-factor authentication information. Charming Kitten has repeatedly demonstrated patience and strong target research, often aligning lures with the victim’s professional interests, geopolitical issues, or current events. Operationally, Charming Kitten has relied heavily on web-based credential harvesting, account takeover, and surveillance-oriented collection rather than overtly destructive activity. The group has also been linked to malware use and broader espionage tooling, but its most characteristic tradecraft remains identity-centric intrusion through social engineering, impersonation, and abuse of trusted services. Reporting has tied the actor to campaigns against academic institutions, foreign policy communities, healthcare and pharmaceutical entities, and government personnel, including efforts to monitor both Iranian citizens and foreign targets assessed to hold intelligence value for the Iranian state. Charming Kitten is part of the broader ecosystem of Iranian intrusion activity and has been repeatedly identified as one of Tehran’s most active espionage operators. Its campaigns reflect a blend of strategic intelligence collection, surveillance of dissidents and civil society, and targeting of foreign governmental and research communities. The group’s sustained activity, adaptive phishing tradecraft, and overlap with other Iranian tracking designations have made it one of the most recognizable Iranian threat actors in public cyber threat intelligence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked threat actor referenced in the context of having its infrastructure, tools, targets, and operational practices exposed by a third party (KittenBusters).
Charming Kitten is an Iranian state-sponsored cyber-espionage group involved in information operations, domain and server infrastructure management, and use of shell companies for operational cover.
Charming Kitten is engaged in phishing and credential harvesting campaigns targeting financial, telecom, and technology sectors, exploiting vulnerabilities in public-facing applications such as Confluence.
Charming Kitten is an IRGC-backed group known for espionage, targeting government, defense, academia, dissidents, and media, primarily in the US, Israel, Europe, and the Middle East. They use spear-phishing, credential harvesting, and exploit Microsoft Exchange vulnerabilities. Recent activities include targeting US election accounts and Israeli cybersecurity experts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.