APT35 is an Iranian state-sponsored cyber espionage actor widely associated with the Islamic Revolutionary Guard Corps, including reporting that links elements of the activity to the IRGC Intelligence Organization. The cluster is tracked under numerous aliases including Charming Kitten, Phosphorus, Mint Sandstorm, TA453, Magic Hound, Cobalt Illusion, Cobalt Mirage, NewsBeef, Newscaster, Agent Serpens, Imperial Kitten, Yellow Liderc, ITG18, Houseblend, Smoke Sandstorm, UNC1549, Nimbus Manticore, Curium, and related designations used by different vendors. Some of these names may refer to overlapping subclusters or partially distinct operational teams rather than a perfectly uniform single entity, but they are consistently tied to Iranian intelligence collection activity. The actor has been active since at least the mid-2010s and is known primarily for espionage, credential theft, and long-term access operations in support of Iranian strategic interests. Targeting has included government officials, diplomats, military personnel, defense contractors, aerospace and aviation organizations, journalists, academics, think tanks, researchers, dissidents, human rights organizations, telecommunications providers, energy firms, healthcare entities, technology companies, and religious or policy figures. Geographic focus has spanned Iran’s regional adversaries and areas of strategic interest, including Israel, Saudi Arabia, the UAE, Jordan, Iraq, Turkey, the broader Middle East, as well as the United States, the United Kingdom, Europe, and parts of South and East Asia. APT35 is especially known for high-touch social engineering. Operators frequently impersonate journalists, recruiters, researchers, policy institutions, podcast hosts, and other trusted personas, often sustaining prolonged email exchanges before delivering phishing links or malware. Campaigns have used fake webinar portals, job offers, interview invitations, healthcare-themed lures, policy documents, and spoofed cloud-service login pages to harvest credentials. The group has also been associated with vishing, spam-bombing as a precursor to phone-based social engineering, and more recently AI-enhanced phishing and voice impersonation. Operational tradecraft includes extensive credential harvesting, account compromise, mailbox theft, and use of valid accounts for follow-on espionage. The actor has repeatedly used fake login pages for major webmail and cloud platforms, and has deployed tooling to extract email contents after obtaining credentials or session material. In parallel with its social-engineering heritage, the group has matured technically and has been observed weaponizing newly disclosed vulnerabilities in public-facing systems, including enterprise email, remote management, collaboration, and edge security products. Reporting also links the actor to exploitation of Microsoft Exchange, Log4Shell-related flaws, Zoho ManageEngine, IBM Aspera Faspex, PaperCut, Fortinet, Zimbra, WinRAR, and other exposed technologies. Malware and tooling associated with APT35 and its related clusters include CharmPower or POWERSTAR, BASICSTAR, BellaCiao, BellaCPP, Hyperscrape, PowerLess, GorjolEcho, KORKULOADER, LittleLooter, Drokbk, BlackSmith, and AnvilEcho, among others. Capabilities observed across these tools include reconnaissance, command execution, persistence, credential and mailbox theft, file discovery, screenshot and audio collection, browser-data theft, keylogging-related collection, payload staging, and data exfiltration. Some operations have used .NET AppDomain hijacking and DLL sideloading chains, including activity attributed to UNC1549 or Nimbus Manticore against aerospace, aviation, defense, and technology targets. Related subgroups have also used dead-drop resolver techniques, cloud-hosted infrastructure, and legitimate services to conceal command-and-control. Commonly reported techniques include spearphishing attachments and links, user-execution lures, PowerShell-based execution, registry-based persistence, registry modification for defense evasion, system, user, network, and file discovery, hidden-window execution, and HTTP or HTTPS command-and-control. The actor has also used cloud services and developer or collaboration platforms as part of delivery, staging, or command infrastructure, and has shown a preference for blending malicious activity with legitimate web traffic and trusted services. APT35 remains one of the most prolific and adaptive Iranian espionage actors. Its operations combine persistent social engineering, credential-centric intrusion methods, selective malware deployment, and increasingly rapid exploitation of newly disclosed vulnerabilities. The group’s activity consistently aligns with Iranian intelligence priorities, particularly surveillance of regional rivals, policy communities, critical sectors, and individuals of strategic interest.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
50 malware families attributed to this actor across reporting.
45 additional families tracked in Mallory.
22 CVEs this actor has used in observed campaigns. 22 of them exploited in the wild.
Microsoft Exchange Server vulnerabilities (e.g., ProxyShell CVE-2021–34473): Exploited to gain initial access.
Log4Shell vulnerabilities (CVE-2021–44228, CVE-2021–45046): Leveraged to deploy PowerShell backdoors like GhostEcho.
Microsoft warns that Iran-linked APT groups have been observed exploiting the CVE-2023-27350 flaw in attacks against PaperCut MF/NG print management servers. The CVE-2023-27350 flaw is a PaperCut MF/NG Improper Access Control Vulnerability. PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of SYSTEM.
FIN7 has compromised targeted organizations through exploitation of CVE-2021-31207 in Exchange. ... Magic Hound has exploited ... ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207)
Log4Shell vulnerabilities (CVE-2021–44228, CVE-2021–45046): Leveraged to deploy PowerShell backdoors like GhostEcho.
17 more CVEs tied to this actor tracked in Mallory.
392 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian APT deploying new RAT variants, using job-lure themes, cloud C2, and AppDomainManager hijacking to disable security mechanisms in .NET applications.
Used recruiter-themed social engineering and job portal impersonation to deliver a .NET AppDomain hijacking sideloading chain for exfiltration and remote control.
Cyber-espionage operations targeting aerospace, aviation, and defense organizations, using fake React-based career portals to deliver multi-stage payloads and exfiltrating data over encrypted C2 channels.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.