APT35 (Charming Kitten): A Strategic Intelligence Report — Evolution, Operations, and Threat…
Executive Summary
APT35 (Charming Kitten): A Strategic Intelligence Analysis— Evolution, Operations, and Threat Outlook (2025)

Executive Summary
Charming Kitten, also known as APT35, is a prolific and adaptable state-sponsored cyber espionage group affiliated with the Iranian government, specifically the Islamic Revolutionary Guard Corps (IRGC). Active since at least 2013–2014, the group has significantly evolved from its early, less sophisticated social media spying campaigns to employing advanced tactics, custom malware, and rapidly weaponizing known vulnerabilities.
Charming Kitten’s primary objectives are cyber espionage and intelligence collection, with a focus on individuals and organizations perceived as threats to the Iranian regime or of strategic value, including those in government, military, media, energy, defense, telecommunications, and academic sectors, particularly across the Middle East, the U.S., and Europe. The group is notable for its persistent and resource-intensive social engineering campaigns, increasingly augmented by Artificial Intelligence (AI). Recent activities through mid-2025 indicate a growing emphasis on AI-driven phishing and continued exploitation of vulnerabilities in widely-used software and public-facing devices.
Cybersecurity professionals will face increasing challenges from APT attackers in 2024 and 2025, necessitating prioritization of countermeasures against supply chain attacks, zero-day vulnerabilities, and intrusions via public-facing devices. Organizations must adopt a multi-layered defense, enhance monitoring for Iranian indicators, and continuously educate employees on evolving social engineering tactics.
Introduction to Charming Kitten (APT35)
Charming Kitten is a prominent state-sponsored cyber threat actor associated with the Iranian government and the Islamic Revolutionary Guard Corps (IRGC). This group has been tracked under numerous aliases by the cybersecurity community, including:
APT35 (Mandiant)
Phosphorus (Microsoft)
Mint Sandstorm (Microsoft, formerly Phosphorus)
Magic Hound (Palo Alto Networks, Secureworks, FireEye)
Newscaster Team (FireEye)
Ajax Security Team (FireEye)
APT42 (Mandiant, Certfa Lab)
TA453 (Proofpoint)
Yellow Garuda
Educated Manticore (Check Point Research)
CharmingCypress
ITG18
NewsBeef (Kaspersky)
UNC788
Agent Serpens
The group’s operations typically involve long-term, resource-intensive campaigns aimed at strategic intelligence collection.
Evolution of Charming Kitten
Charming Kitten’s activity has been observed as early as 2004–2007, with other sources indicating active operations since 2011–2012 (under aliases like Newscaster and Parastoo), and more widely identified since 2013–2014 by cybersecurity firms like FireEye.
Initially, the group was known for social media-based spying campaigns and was characterized by less sophisticated hacking skills, often compensating for a lack of technological prowess with extensive social engineering. Their early efforts focused on compromising email accounts and machines through various techniques.
Since 2021, Charming Kitten has significantly stepped up its capabilities, developing custom tools and demonstrating the ability to rapidly weaponize vulnerabilities, sometimes within a day of their public disclosure. This evolution includes the development of malware such as BELLACIAO (and its C++ variant BellaCPP), HYPERSCRAPER (for email extraction), and updates to backdoors like POWERSTAR (also known as CharmPower or GhostEcho).
There has also been a notable shift in their targeting and motivation. While historically focused on dissidents and scholars, the group has expanded its activities to include ransomware attacks and critical infrastructure targeting. Although they temporarily engaged in financially motivated attacks, such as deploying Memento ransomware, they have largely returned to their core espionage objectives. This shift aligns with a faster adoption of newly reported vulnerabilities and the use of compromised websites for Command and Control (C2) to obscure attack origins. The group’s activities have become harder to predict due to this versatility in modus operandi, targeting, and motivation.
Tactics, Techniques, and Procedures (TTPs)
Charming Kitten’s TTPs are characterized by persistence, adaptability, and an increasing level of sophistication.
· Initial Access and Social Engineering
The group’s primary method for initial access is spear phishing. They craft highly tailored messages that appear to come from legitimate, trusted sources, sometimes even from compromised legitimate email accounts.
· Social engineering is a core component of their approach, involving:
Impersonation: Posing as journalists, former Wall Street Journal reporters, assistants to tech executives or researchers, or even model agencies.
Lures: Using hard-to-resist lures such as healthcare alerts, job postings, resumes, urgent password policy updates, fake interview requests, fake webinar portals, or documents related to U.S. foreign policy.
Building trust: Engaging targets in prolonged conversations over email, sometimes for several days, before sending malicious content. They use Multi-Persona Impersonation (MPI), involving multiple threat-actor-controlled email accounts.
Credential Harvesting: Directing victims to fake login pages for services like Gmail, Google Meet, Microsoft OneDrive, Yahoo, or other legitimate webmail services to steal credentials.
Vishing (Voice Phishing): Utilizing persuasive social engineering techniques via phone calls, sometimes amplified by AI-generated voice clones to impersonate IT staff. Spam bombing with thousands of emails can be used as a pretext for vishing calls.
Malware and Custom Toolset
Charming Kitten deploys a mix of custom-developed and open-source tools to achieve its objectives:
Backdoors: CharmPower (also known as GhostEcho or POWERSTAR), PowerLess (a PowerShell backdoor), BASICSTAR, and GorjolEcho. These backdoors enable information exfiltration, module downloads, and persistent remote control.
Data Exfiltration Tools: Hyperscrape, used to quietly extract emails from Yahoo!, Google, and Microsoft Outlook mailboxes once valid credentials or session cookies are obtained.
Info Stealers & Keyloggers: The group’s toolkit includes browser info stealers and keyloggers. LittleLooter is a custom Android backdoor with information-stealing capabilities.
Wiper Malware: StoneDrill, similar to Shamoon2 malware, was used in some campaigns.
Droppers: BellaCiao (and BellaCPP) is a personalized dropper capable of delivering other malware payloads based on C2 commands. KORKULOADER is a PowerShell downloader script.
Other Tools: They have used the DiskCryptor library, BitLocker, and Fast Reverse Proxy (FRP). They also leverage PowerShell scripts due to their ability to blend with normal system activity.
Vulnerability Exploitation
Charming Kitten is known for its ability to quickly weaponize both zero-day and N-day vulnerabilities. This often involves exploiting common software vulnerabilities, public network device vulnerabilities, and driver vulnerabilities.
Pattern in Exploited Vulnerabilities and Technologies: An interesting pattern observed is the group’s opportunistic approach to exploiting widely-used software and public-facing infrastructure, aligning with an “opportunity-oriented” rather than solely “goal-oriented” strategy. This allows for large-scale cyber-attack operations to then identify high-value targets from the compromised pool.
The group extensively exploits vulnerabilities in web-facing applications, mail servers, and collaboration platforms, likely due to their pervasive use and often complex update channels.
Specific vulnerabilities and affected products include:
• WinRAR Logical RCE vulnerability (CVE-2023–38831): Exploited in zero-day attacks, its wide installation base and difficult update channels make it a significant weapon for breakthrough attacks.
• TeamCity Server RCE vulnerability (CVE-2023–42793): Exploited by APT29 (CozyBear), a group sometimes linked to Charming Kitten (though APT29 is Russian, not Iranian).
• Microsoft Exchange Server vulnerabilities (e.g., ProxyShell CVE-2021–34473): Exploited to gain initial access.
• Log4Shell vulnerabilities (CVE-2021–44228, CVE-2021–45046): Leveraged to deploy PowerShell backdoors like GhostEcho.
• Zoho ManageEngine vulnerabilities (CVE-2022–47966): Exploited for initial intrusion.
• IBM Aspera Faspex (CVE-2022–47986).
• PaperCut MF/NG print management servers (CVE-2023–27350).
• Fortinet FortiOS vulnerabilities (CVE-2018–13379, CVE-2020–12812, CVE-2019–5591).
• Various other vulnerabilities: Including Local File Inclusion in Gradio (CVE-2024–1561), SQL Injection in CZ Loan Management WordPress plugin (CVE-2024–5975), OS Command Injection in PHP-CGI (CVE-2024–4577), Information Disclosure in DomPDF (CVE-2014–2383), Remote Code Execution in Apache Struts (CVE-2017–5638), Unauthorized Access to Oracle WebCenter Sites (CVE-2018–3238), OGNL Injection in Confluence Server and Data Center (CVE-2021–26084), SQL Injection in Apache Skywalking (CVE-2020–9483), Code Injection in PHPunit (CVE-2017–9841), Missing Authentication in F5 BIG-IP (CVE-2022–1388), and credential harvesting from Cisco ASA WebVPN users.
• DrayTek Router Vulnerabilities (CVE-2024–7261).
• Critical Zimbra Vulnerability (CVE-2024–45519).
• Microsoft Elevation of Privilege Vulnerability (CVE-2024–38189).
Persistence and Lateral Movement
To maintain a persistent presence, Charming Kitten uses credential theft and deploys additional malware for continuous access. They establish persistence through techniques like web shells on compromised servers or by creating scheduled tasks. After gaining a foothold, they move laterally across networks using stolen credentials and exploiting trust relationships within the victim’s infrastructure to access more sensitive areas.
Evasion Techniques
Charming Kitten employs sophisticated evasion techniques to avoid detection:
• High-level obfuscation and custom code: Designed to bypass security tools that rely on identifying known malware signatures or behaviors.
• Encrypted communication channels: Used for C2 interactions.
• Mimicking legitimate activities: Their malware often tries to behave like legitimate web browser activities to evade Network Intrusion Detection Systems (NIDS).
• Avoiding frequent connection termination and resumption: To increase stealthiness, APTs tend to terminate connections less frequently than legitimate or botnet traffic.
• Using cloud hosting providers: Leveraging platforms like Google Scripts, Dropbox, and CleverApps to deliver malware complicates tracking and minimizes detection.
Target Profiles
Charming Kitten’s target selection is strategic, aligning with Iranian geopolitical and intelligence interests.
Geographic Focus
The group’s operations span various regions:
• Middle East: Particularly Israel, Saudi Arabia, UAE, Iraq, and Jordan.
• United States.
• Europe: Including the UK, France, Germany, Netherlands, and Albania.
• South Asia.
• East Asia and Southeast Asia.
• Turkey, India.
Sectoral Targets
Charming Kitten focuses on high-value individuals and critical sectors that can provide insights into geopolitical issues and strategic interests.
• Government Agencies and Diplomacy: Including U.S. government officials, military personnel, and diplomats.
• Academia and Research Institutions: Professors, academic researchers, and think tanks specializing in Middle Eastern policy, nuclear security, oncology, genetics, and neurology.
• Media: Journalists, news editors, and media outlets. The group has been linked to the 2017 HBO ransomware attack.
• Defense Industrial Base (DIB).
• Energy and Critical Infrastructure: Including oil and gas industries, and broader critical infrastructure globally.
• Financial Services: Although less common, they have been observed to target financial organizations.
• Telecommunications.
• Healthcare: Including medical research organizations and hospitals.
• Civil Society Organizations: Human rights activists and dissidents.
Role of Artificial Intelligence (AI) in Operations
A significant development in Charming Kitten’s operational methodology since mid-2025 is the adoption of AI-enhanced social engineering tactics. This represents a transformation from traditional surveillance to more sophisticated, high-trust social engineering attacks.
• AI-Crafted Lures: They are using AI tools to deliver highly polished and convincing phishing messages via email and WhatsApp. These AI-generated emails are designed to build rapport over extended periods, sometimes weeks or months, through highly personalized and contextually relevant communications based on publicly available information about targets.
• Profiling: AI can rapidly scrape social media to generate detailed profiles, which aids in tailoring convincing phishing emails, fake documents, and spoofed websites.
• Leveraging AI Platforms: Google has reported that Iranian threat actors are using its Gemini AI platform for these purposes.
This integration of AI allows Charming Kitten to make their attacks more scalable and precise, blurring the lines between traditional cyber warfare and psychological manipulation.
Key Individuals/Connections
Charming Kitten is a state-sponsored group with direct affiliation to the Islamic Revolutionary Guard Corps (IRGC). Their targeting and intelligence collection objectives consistently align with the IRGC’s interests.
Notable individuals linked to Charming Kitten’s activities include:
• Monica E. Witt: A former U.S. Air Force technical sergeant who defected to Iran in 2014 and became involved in Iranian espionage campaigns targeting U.S. intelligence.
• Behzad Mesri (aka Sokoote Vahshat): The hacker who claimed responsibility for the 2017 HBO hack and was later indicted. His association with the “Turk Black Hat Security Team,” which provided infrastructure for Charming Kitten, established a link.
The group often overlaps with other Iranian threat groups, including those designated as APT42, Mint Sandstorm, TA453, and Yellow Garuda, indicating a complex and sometimes shared ecosystem of Iranian cyber operations.
Recent Activities (2024-Mid 2025)
Charming Kitten has maintained a high operational tempo and continued its evolution through 2024 and into mid-2025:
• New Malware Variants: In December 2024, they deployed BellaCPP, a new C++ variant of the BellaCiao malware.
• AI-Enhanced Phishing Campaigns: Since mid-2025, APT35 has intensified its cyber-espionage operations, particularly against Israeli targets, using AI-enhanced phishing tactics to target journalists, cybersecurity experts, and computer science professors. This includes AI-enhanced social engineering via malicious PDFs masquerading as RAND documents.
• Focus on Middle East Policy Experts: In February 2024, Charming Kitten was linked to attacks targeting Middle East policy experts with a new backdoor called BASICSTAR, delivered through fake webinar portals. These campaigns involved multi-persona impersonation and using compromised email accounts of legitimate contacts.
• Exploiting Latest Vulnerabilities: The group was observed exploiting new vulnerabilities in Albania as of November 2024, including CVE-2024–1561 (Gradio), CVE-2024–5975 (CZ Loan Management WordPress plugin), and CVE-2024–4577 (PHP-CGI).
• Updated Powerstar Backdoor: As of July 2023, Charming Kitten updated its Powerstar backdoor (CharmPower), exhibiting improved operational security measures and the ability to execute PowerShell and CSharp commands.
• Persistent Credential Phishing: As of October 2024, the group continues to create new network infrastructure for credential phishing, targeting individuals perceived as threats to the Iranian regime, including researchers, journalists, NGO leaders, and human rights activists in the U.S., Israel, and Europe.
APT Landscape – Future Trends and Threat Predictions
Looking ahead to 2025 and beyond, several trends indicate an escalating and evolving threat landscape posed by Charming Kitten and similar APT groups:
• Increased Attack Volume and Sophistication: China experienced a record number of APT attacks in 2023, and the number of global APT activities reached a new high, with a 26.9% increase in attack leads observed by NSFOCUS’s Fuying Lab. This upward trend in activity and sophistication is expected to continue.
• AI-Driven Cyber Warfare: AI will continue to play a pivotal role in sophisticated cyberattack campaigns. Expect AI to be increasingly used for hyper-targeted social engineering, generating detailed target profiles, creating convincing phishing emails, fake documents, and spoofed websites.
• Continued Focus on Indirect Attack Patterns: APT groups will extensively practice indirect attack patterns, such as controlling software supply chains, infrastructure, and invading boundary devices. This “opportunity-oriented” approach will lead to large-scale operations to screen for high-value targets.
• Rapid Weaponization of Vulnerabilities: The ability to quickly weaponize newly disclosed vulnerabilities (N-days) and zero-days will remain a key tactic. Cybersecurity professionals must prioritize countermeasures against zero-day vulnerabilities and intrusions via public-facing devices.
• Exploitation of Common Software and Infrastructure: The focus on vulnerability risks in commonly used software, enterprise software, mail servers, security devices, communication equipment, and business infrastructure will intensify, as these serve as channels for indirect APT attacks.
• Declining Breakout Times: The average breakout time (time to move laterally across a network) reached an all-time low of 48 minutes in 2024, with the fastest observed at 51 seconds. This necessitates extremely rapid detection and response capabilities.
• Ransomware Integration: State-sponsored hackers, including Iranian groups, are increasingly incorporating ransomware into their arsenals, potentially collaborating with financially motivated groups like Scattered Spider.
• Focus on Critical Infrastructure: Continued targeting of critical infrastructure sectors will pose a severe test to cybersecurity systems.
• Enhanced OPSEC: Threat actors, including China-nexus adversaries (a general trend that can apply to other advanced groups), will increasingly prioritize operational security (OPSEC) to obfuscate their activities.
• Geopolitical Influence: Geopolitical tensions, particularly in the Middle East, will continue to drive Iranian cyber activities and target selection.
• Evolving Target Scope: Charming Kitten is expected to increase its interest in cyber espionage against individuals who are experts in different areas in the Middle East and North Africa.
Conclusion
Charming Kitten (APT35) remains a highly active and dangerous state-sponsored cyber espionage group. Their continuous evolution in tactics, including the increasing sophistication of social engineering campaigns through AI and rapid exploitation of vulnerabilities, underscores the dynamic nature of the cyber threat landscape. Organizations, particularly those in critical sectors or with interests in geopolitically sensitive regions, must acknowledge the persistent threat posed by Charming Kitten. By proactively strengthening defenses, investing in human-centric security awareness, and adopting a comprehensive, intelligence-driven approach, organizations can enhance their resilience and effectively counter these enterprising adversaries. The digital battlefield is indeed heating up, and constant vigilance and adaptation are the keys to defense.
메타데이터
- post_id
- 862eea4a2db4
- slug
- apt35-charming-kitten-a-strategic-intelligence-report-evolution-operations-and-threat-862eea4a2db4
- url
- https://medium.com/@raghavtiresearch/apt35-charming-kitten-a-strategic-intelligence-report-evolution-operations-and-threat-862eea4a2db4
- canonical_url
- https://medium.com/@raghavtiresearch/apt35-charming-kitten-a-strategic-intelligence-report-evolution-operations-and-threat-862eea4a2db4
- author_url
- https://medium.com/@raghavtiresearch
- status
- ok
- fetched_at
- 2026-06-25 07:00:49