Hyperscrape
Hyperscrape is a tool developed by the Iranian government-sponsored threat group APT35 (also known as Charming Kitten and Phosphorus). It is designed to log in to victim Gmail and Microsoft accounts and silently exfiltrate emails. The supporting content places Hyperscrape within APT35’s broader credential-theft and cloud account targeting operations, which have focused on Microsoft 365, Gmail, and cloud VPN portals using phishing, password spraying, stolen credentials, and token theft. APT35 has targeted military, diplomatic, and government personnel in the United States, Europe, and the Middle East, as well as researchers, media organizations, energy entities, and defense contractors. No specific indicators of compromise for Hyperscrape are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT35 developed a tool called Hyperscrape designed to log in and silently exfiltrate emails from victim Gmail and Microsoft accounts.
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom APT35 tool used to authenticate to victim Gmail/Microsoft accounts and silently exfiltrate email data.
A data-exfiltration tool used to log into victim Gmail and Microsoft accounts and silently steal emails.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.