A public leak tied to Charming Kitten, the Iranian threat group also tracked as an IRGC-linked operation, exposed material described as documenting the group's malicious activity and its connection to the IRGC-IO counterintelligence division known as 1500. A GitHub repository published under the name KittenBusters/CharmingKitten presented the leak as evidence of the group's internal operations, adding to public scrutiny of one of Tehran's most prominent cyber-espionage actors.
Follow-on reporting said the leak continued with the release of payroll data and a stolen IAEA document, suggesting the exposed archive extended beyond operational details into sensitive internal records and potentially intelligence-related material. The disclosures indicate a sustained effort to reveal the infrastructure, personnel, and document holdings associated with Charming Kitten, raising counterintelligence and diplomatic concerns around the handling of stolen data linked to an Iranian state-aligned cyber unit.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A later blog post stated that the Charming Kitten leak was continuing and described the release of payroll data along with a stolen IAEA document, indicating a further disclosure of allegedly compromised materials.
A blog post published by Nariman Gharib described alleged details about IRGC Department 40, presenting it as a unit connecting cyber operations to assassination activity. The post appears to represent a new phase of disclosures following the initial Charming Kitten repository publication.
A GitHub repository titled "KittenBusters/CharmingKitten" was published, presenting materials that purported to expose malicious activity linked to Charming Kitten and the IRGC-IO counterintelligence division known as Unit 1500.
3 references tracked. Mallory keeps watching after this page renders.
blog.narimangharib.com
Open sourceblog.narimangharib.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.