Microsoft, Volexity, Check Point, and PwC reported that the Iranian threat actor tracked as Mint Sandstorm—also known as APT35, PHOSPHORUS, and Charming Kitten—has expanded both its intrusion and espionage tradecraft. The group combined rapid exploitation of internet-facing vulnerabilities, including Log4Shell and other N-day flaws, with tightly targeted phishing against high-value victims in critical infrastructure, think tanks, universities, and related sectors. Microsoft said the actor moved from reconnaissance to direct targeting of U.S. critical infrastructure organizations, including entities in energy, transportation, transit, seaports, and utilities, while also pursuing credential theft, lateral movement, and persistence inside compromised environments.
Researchers also documented major updates to the actor’s CharmPower/POWERSTAR PowerShell malware. Volexity found newer variants delivered through long-running social-engineering lures, including journalist impersonation and password-protected archives containing malicious shortcut files, then staged and executed largely in memory. The malware now supports remote PowerShell and C# execution, modular reconnaissance and collection, multiple persistence options, dynamic configuration updates, and resilient command-and-control through cloud services and IPFS, complicating disruption and takedown efforts.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
In May 2023, Volexity observed Charming Kitten impersonate a reporter from an Israeli media organization, build trust with a target over several days, and then send a password-protected RAR archive containing a malicious LNK file. The LNK fetched the initial POWERSTAR script from a Backblaze B2 bucket and executed it in memory.
In April 2023, Microsoft reported Mint Sandstorm distributing OneDrive-hosted PDF files containing URLs leading to a Dropbox-hosted DOTM that used template injection to execute POWERSTAR. Microsoft said these low-volume phishing campaigns targeted individuals tied to think tanks and universities in Israel, North America, and Europe.
Microsoft said the subgroup exploited CVE-2022-47986 in IBM Aspera Faspex within five days of a public proof of concept released on February 2, 2023. This reflected continued rapid adoption of public exploit material.
Microsoft reported that the subgroup began exploiting CVE-2022-47966 in Zoho ManageEngine on January 19, 2023, the same day a public proof of concept became available. The event showed rapid weaponization of newly public exploit code.
In July 2022, PwC reported Yellow Garuda distributing DOCX files hosted on Dropbox and AWS that abused template injection to execute DOTM files and decrypt POWERSTAR using keys fetched from S3 buckets. This documented another delivery evolution for the malware.
Microsoft stated that the U.S. Department of the Treasury sanctioned elements of Mint Sandstorm in 2022 for past cyberattacks and cited IRGC sponsorship. This was a government action tied to the actor's prior operations.
Microsoft said it had observed the Mint Sandstorm subgroup using the custom implants Drokbk and Soldier since 2022. The tools were used in post-compromise activity and relied on actor-controlled GitHub repositories for domain rotators.
In January 2022, Check Point publicly reported Charming Kitten exploiting Log4J and then executing POWERSTAR hosted on an Amazon S3 bucket. The reporting tied the actor's exploitation activity to delivery of the malware.
Microsoft reported that from late 2021 to mid-2022, a mature Mint Sandstorm subgroup shifted from reconnaissance to direct targeting of U.S. critical infrastructure. Targets included seaports, energy companies, transit systems, and a major U.S. utility and gas entity.
Volexity first encountered POWERSTAR in 2021 and observed it distributed via a malicious macro embedded in a DOCM file. This establishes the earliest referenced appearance of the malware family later tracked as CharmPower.
Volexity analyzed the newly observed POWERSTAR variant and found stronger operational security, staged in-memory execution, remotely hosted decryption logic, dynamic configuration updates, and use of Backblaze, Clever Cloud, and IPFS. Volexity also obtained nine modules, including screenshot capture, persistence, file crawling, and cleanup capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
volexity.com
Open sourcemicrosoft.com
Open sourcepwc.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.