Magic Hound, commonly known as Charming Kitten, is an Iranian state-sponsored cyber-espionage threat actor linked to the Islamic Revolutionary Guard Corps (IRGC) and active since at least 2014. It is also tracked as APT35, Phosphorus, Mint Sandstorm, NewsBeef, and ITG18. The group conducts surveillance and intelligence collection against Iranian and foreign individuals and organizations of strategic interest to the IRGC. Its targets have included academics, journalists, human-rights activists, the Baha'i community, government officials, medical and COVID-19-related organizations, and organizations in the energy, government, technology, financial, and telecommunications sectors. Documented targeting includes organizations and individuals in the United States, Israel, France, Europe, and the Middle East. Magic Hound uses phishing and credential-harvesting operations for initial access. Associated malware has captured screenshots, collected usernames, recorded keystrokes, and transmitted collected data to command-and-control infrastructure. Custom malware including CWoolger and MPK has been used for keylogging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
55 malware families attributed to this actor across reporting.
50 additional families tracked in Mallory.
32 CVEs this actor has used in observed campaigns. 32 of them exploited in the wild.
CISA and the FBI issued a joint advisory warning of ongoing exploitation of the Log4Shell vulnerability (CVE-2021-44228) on November 16. The advisory noted that an unspecified Iran-linked threat actor group had exploited the vulnerability during an intrusion into a Federal Civilian Executive Branch (FCEB) organization’s network earlier this year.
The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities. Thanks to Deep Instinct’s prevention capabilities the threat actor was unsuccessful in executing the payloads in a customer environment despite successful exploitation of the Exchange server.
The critical PaperCut remote-code-execution vulnerability CVE-2023-27350 and high-severity information-disclosure flaw CVE-2023-27351 were exploited together in April 2023 attacks linked to LockBit and Clop. Bl00dy later used CVE-2023-27350 for initial access.
Although they required several weeks to weaponize Log4Shell in 2022, the initial attempts to exploit CVE-2022-47966 in Zoho ManageEngine were identified on the same day the PoC was made public.
CVE-2023-27351 is a high-severity information-disclosure vulnerability that was exploited together with CVE-2023-27350 in April 2023 PaperCut attacks linked to LockBit, Clop, MuddyWater, and APT35.
27 more CVEs tied to this actor tracked in Mallory.
863 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian state-backed activity linked to exploitation of PaperCut vulnerabilities in 2023, including abuse of the Print Archiving feature.
Iranian state-backed group that participated in 2023 PaperCut exploitation and abused the Print Archiving feature to save documents sent through compromised print servers.
Mentioned only as the broader cluster that includes Tortoiseshell.
Named parent cluster containing Tortoiseshell, which is linked to the activity discussed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.