Leaked internal documents and previously exposed operator recordings have provided an unusually detailed view into the operations of Charming Kitten—also tracked as APT35, Phosphorus, and Mint Sandstorm—an Iranian state-linked cyber-espionage group reportedly affiliated with the IRGC. The leaked cache published in late 2025 described formal command structures, campaign workflows, target lists, and attack playbooks, while earlier video footage reportedly captured operators conducting intrusions and stealing data from email accounts after accidentally exposing recordings on an internet-accessible server. Together, the materials depict a mature intelligence operation using phishing, credential harvesting, web shells, OSINT, mass scanning, and exploitation of vulnerabilities in products including ConnectWise, Ivanti Connect Secure, PHP-CGI, Telerik UI, Confluence, GitLab, WordPress plugins, and Jenkins.
The exposed records indicate that APT35 conducted both targeted and opportunistic campaigns across the Middle East, including activity affecting government bodies, telecom systems, legal entities, and internet-facing infrastructure in Israel, Jordan, Afghanistan, Saudi Arabia, Turkey, and the United Arab Emirates. Reported theft included 74 GB of data tied to Jordan-linked targets and thousands of emails from Afghan ministries. Separate infrastructure analysis in 2026 also found domains and rogue mail subdomains likely prepared for phishing against Egyptian shipping and marine services companies, with researchers linking the setup to Iran-aligned activity consistent with APT35 and suggesting possible compromise of legitimate DNS or cPanel configurations to support the operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A leaked cache of internal documents exposing Charming Kitten’s organization, workflows, targets, and attack methods was published. The materials included campaign briefs, target lists, exploitation guides, scan reports, credentials, databases, and evidence of compromises across multiple Middle Eastern countries.
Charming Kitten launched the opportunistic Operation Swiftstrike against targets in Turkey, Saudi Arabia, Jordan, and the United Arab Emirates. The campaign used mass scanning and internet-wide search tools alongside exploitation of ConnectWise and Ivanti vulnerabilities.
Operation Desert Breach began targeting Jordan, including the Ministry of Justice, academic institutions, and legal professionals such as law firms. The campaign relied heavily on exploitation of CVE-2012-1823 and used web shells for persistence, resulting in more than 74 GB of exfiltrated data.
Charming Kitten ran Operation Shattered Mirror against Israel, compromising modems, routers, and commercial websites to support surveillance and credential collection. The operation also included phishing political opponents of the Israeli government using fake conference entry cards.
Charming Kitten conducted Operation Afghan Infiltration against Afghan telecommunications systems and government bodies, including the Ministry of Tribal and Border Affairs and the Ministry of Refugees and Repatriation. The campaign enabled exfiltration of emails and internal accounts to support long-term surveillance.
IBM’s Black Hat presentation states that Microsoft won a criminal complaint in March 2019 that sinkholed 99 ITG18 domains, including identifier-services-sessions.info on March 27, 2019. IBM said the actor adapted about three weeks later by shifting to a replacement domain, identifier-services-session.site.
SecurityScorecard reported that domains and rogue subdomains tied to infrastructure associated with Iran-linked activity were likely prepared for phishing campaigns targeting Egypt-based shipping and marine services companies and other regional organizations. The company assessed with high confidence that the targeting pattern and infrastructure overlap were consistent with APT35/Charming Kitten.
Google Threat Analysis Group published reporting on the Iranian HYPERSCRAPE data extraction tool and identified command-and-control infrastructure including 136.243.108[.]14 in Germany and 173.209.51[.]54 in Canada. This reporting later served as a pivot point for SecurityScorecard’s infrastructure analysis.
IBM’s X-Force security team obtained roughly five hours of recordings that appeared to show APT35 operators conducting hacking activity. The footage reportedly exposed how the group stole data from email accounts and identified targets after the videos were allegedly uploaded to an unprotected internet-accessible server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcegatewatcher.com
Open sourcewired.com
Open sourcei.blackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.