Charming Kitten is an Iranian cyber-espionage threat actor widely associated with APT35 and linked in reporting to Unit 1500 of the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). The group is known for intelligence collection operations aligned with Iranian state interests. Reporting has tied the actor to operational infrastructure procurement and registration activity that used the address of a real Dutch bakery as cover, illustrating the use of spoofed or deceptive registration details to support operations. Charming Kitten is best characterized as a state-aligned espionage actor rather than a financially motivated cybercriminal group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked espionage actor described as using a real Dutch bakery address as cover/false registration details when procuring infrastructure (servers/domains), consistent with operational security and attribution-evasion tradecraft.
Iranian cyber-espionage group; subject of repeated data leaks exposing tooling, operations, and alleged members/front companies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.