State-backed advanced persistent threat (APT) groups have intensified their cyber espionage activities, employing increasingly sophisticated tactics, techniques, and procedures (TTPs) to infiltrate and persist within high-value targets. APT15, believed to operate out of China, has conducted a series of high-profile campaigns targeting government entities, defense contractors, and minority groups across Europe, North America, and Asia. Their operations leverage spear phishing, exploitation of public-facing applications, and advanced defense evasion methods such as steganography and masquerading malware as legitimate software. Similarly, the Iranian group Charming Kitten (APT35) has been exposed through recent leaks, revealing the identities of key personnel, financial structures, and thousands of compromised systems worldwide. These leaks detail how the group uses spear-phishing, fake login pages, and malicious attachments to gain initial access, followed by persistent surveillance and data exfiltration from government, academic, and civil society networks.
Technical analysis of these groups' operations highlights the use of legitimate system tools for lateral movement and persistence, as well as complex command-and-control (C2) infrastructures designed to evade detection. The leaks concerning Charming Kitten provide unprecedented insight into the operational management and financial underpinnings of Iranian cyber espionage, including the use of front companies and detailed tasking sheets. Both APT15 and APT35 demonstrate the ongoing evolution of state-sponsored cyber threats, with a focus on stealth, persistence, and the targeting of sensitive information across multiple sectors and geographies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Leaked internal materials attributed to Iran-linked Charming Kitten (APT35) reportedly revealed operator identities, organizational structure, front companies, financial routing details, and thousands of compromised systems across five continents.
Microsoft disrupted APT15 operations in 2021 by seizing infrastructure associated with the group. The reporting says the group continued operating afterward and adapted with new tooling and relay methods.
APT15, also known as Ke3chang, NICKEL, and VIXEN PANDA, is described as a China-based espionage group that has been active since around 2010, targeting government, diplomatic, and military sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.