{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "apt35",
    "slug": "apt35",
    "name": "APT35",
    "shortName": "APT35",
    "country": "Iran",
    "countryCode": "IR",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2013",
    "prominence": 87,
    "mitreGroupId": "G0059",
    "malpediaSlug": "charming_kitten",
    "tagline": "IRGC-linked social engineering specialists. Will spend weeks impersonating a journalist or academic before ever sending a link.",
    "bio": "APT35 — most commonly known as Charming Kitten — invests more effort in human manipulation than almost any other state actor, and it shows in the results.\n\nOperators build durable fictitious personas: journalists from real outlets, conference organisers, researchers at recognisable think tanks. They make contact over weeks, sometimes months. They hold genuine conversations about the target's actual work. Several documented operations used multiple coordinated personas who referenced each other to manufacture credibility, and at least one used a fake video conference in which the target believed they were speaking with a real institution.\n\nOnly after trust is established does the malicious link appear — usually a credential-harvesting page for a webmail or SSO service, delivered via a real-time proxy that captures the session token and defeats MFA.\n\nThe targeting is politically specific and often personal: Iranian dissidents and journalists in exile, academics researching Iran, nuclear policy specialists, government officials, and — notably — the families of targets, approached as a route to the primary. During the 2020 and 2024 U.S. election cycles the group targeted campaign staff, and in 2024 the Department of Justice indicted three IRGC-affiliated individuals over a hack-and-leak operation against a U.S. presidential campaign.\n\nThe 2019 Microsoft disclosure of \"Phosphorus\" targeting a U.S. presidential campaign, and the 2022 CISA advisory on the group's Log4Shell exploitation of unpatched VMware Horizon servers, mark the two poles of its capability: sophisticated social engineering at the front, opportunistic mass exploitation when a good bug appears.",
    "attribution": {
      "sponsor": "Iran",
      "service": "Islamic Revolutionary Guard Corps (IRGC)",
      "unit": "IRGC-affiliated contractors, including Emennet Pasargad and Mahak Rayan Afraz",
      "confidence": "high",
      "summary": "Assessed as operating on behalf of the IRGC. The U.S. Department of Justice indicted three IRGC-affiliated individuals in September 2024 over a hack-and-leak operation against a U.S. presidential campaign, and the Treasury has sanctioned multiple IRGC-linked front companies for related activity, including Emennet Pasargad. Attribution to the IRGC rather than the MOIS is based on targeting patterns, contractor relationships, and U.S. government statements, though the boundaries between Iranian contractor clusters are less clearly established than for Russian or Chinese services.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Three IRGC Cyber Actors Indicted for Hack-and-Leak Operation Targeting a U.S. Presidential Campaign",
          "url": "https://www.justice.gov/opa/pr/three-iranian-nationals-charged-hacking-and-leaking-campaign-designed-influence-2024-us",
          "date": "2024-09-27"
        },
        {
          "org": "CISA / FBI / NSA and partners",
          "title": "Iranian Government-Sponsored APT Actors Compromise Federal Network with Log4Shell (AA22-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-320a",
          "date": "2022-11-16"
        },
        {
          "org": "Microsoft Threat Intelligence",
          "title": "Recent cyberattacks require us all to be vigilant (Phosphorus targeting of a U.S. presidential campaign)",
          "url": "https://blogs.microsoft.com/on-the-issues/2019/10/04/recent-cyberattacks-require-us-all-to-be-vigilant/",
          "date": "2019-10-04"
        }
      ]
    },
    "motivations": [
      "espionage",
      "information-operations"
    ],
    "targetSectors": [
      "Government",
      "Think Tanks & Academia",
      "Media & Journalism",
      "NGO & Civil Society",
      "Defense",
      "Political Organizations",
      "Energy",
      "Healthcare",
      "Education"
    ],
    "targetCountries": [
      "United States",
      "Israel",
      "United Kingdom",
      "Saudi Arabia",
      "Iran",
      "Germany",
      "France",
      "United Arab Emirates"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Magic Hound",
        "url": "https://attack.mitre.org/groups/G0059/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Mint Sandstorm",
        "correlation": "exact",
        "note": "Formerly PHOSPHORUS"
      },
      {
        "org": "microsoft",
        "name": "PHOSPHORUS",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Charming Kitten",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT35",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "COBALT ILLUSION",
        "correlation": "exact"
      },
      {
        "org": "proofpoint",
        "name": "TA453",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Charming Serpens",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "ITG18",
        "correlation": "partial",
        "note": "IBM X-Force designator, widely cross-referenced"
      },
      {
        "org": "cisa",
        "name": "Charming Kitten",
        "correlation": "exact"
      },
      {
        "org": "trendmicro",
        "name": "Earth Vetala",
        "correlation": "partial",
        "note": "Partial overlap with tracked activity"
      }
    ],
    "tools": [
      {
        "name": "POWERSTAR / GorjolEcho",
        "type": "backdoor",
        "custom": true,
        "description": "PowerShell backdoor delivered after extended rapport-building, with validation logic that decrypts only on the intended host."
      },
      {
        "name": "HYPERSCRAPE",
        "type": "utility",
        "custom": true,
        "description": "Mailbox exfiltration tool that downloads messages and restores their unread status to conceal the theft."
      },
      {
        "name": "Evilginx-style AiTM proxies",
        "type": "framework",
        "custom": false,
        "description": "Real-time credential proxies capturing session cookies to defeat MFA."
      },
      {
        "name": "BellaCiao",
        "type": "backdoor",
        "custom": true,
        "description": "Personalised dropper compiled per-victim, with the target's organisation encoded in the binary and DNS-based activation."
      },
      {
        "name": "Fake video conferencing",
        "type": "utility",
        "custom": false,
        "description": "Staged online meetings used to build credibility before delivering a malicious link."
      },
      {
        "name": "PowerLess",
        "type": "backdoor",
        "custom": true,
        "description": "PowerShell backdoor with keylogging, browser credential theft, and screenshot capability."
      }
    ],
    "techniques": [
      {
        "tCode": "T1585.001",
        "name": "Establish Accounts: Social Media Accounts",
        "tactic": "Resource Development",
        "note": "Long-lived personas with genuine posting history"
      },
      {
        "tCode": "T1585.002",
        "name": "Establish Accounts: Email Accounts",
        "tactic": "Resource Development",
        "note": "Multiple coordinated personas referencing each other for credibility"
      },
      {
        "tCode": "T1598.003",
        "name": "Phishing for Information: Spearphishing Link",
        "tactic": "Reconnaissance",
        "note": "Weeks of benign correspondence before any payload"
      },
      {
        "tCode": "T1566.002",
        "name": "Phishing: Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1557",
        "name": "Adversary-in-the-Middle",
        "tactic": "Credential Access",
        "note": "Real-time credential proxying to capture MFA-backed sessions"
      },
      {
        "tCode": "T1539",
        "name": "Steal Web Session Cookie",
        "tactic": "Credential Access"
      },
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "note": "Log4Shell against unpatched VMware Horizon servers"
      },
      {
        "tCode": "T1114.002",
        "name": "Email Collection: Remote Email Collection",
        "tactic": "Collection",
        "note": "HYPERSCRAPE bulk mailbox theft"
      },
      {
        "tCode": "T1136.001",
        "name": "Create Account: Local Account",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1059.001",
        "name": "Command and Scripting Interpreter: PowerShell",
        "tactic": "Execution"
      },
      {
        "tCode": "T1102.002",
        "name": "Web Service: Bidirectional Communication",
        "tactic": "Command and Control"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2021-44228",
        "firstExploited": "2022-02-01",
        "usage": "Log4Shell exploited against an unpatched VMware Horizon server at a U.S. federal civilian agency, leading to XMRig cryptomining, credential harvesting, and lateral movement — documented in detail by CISA.",
        "source": {
          "org": "CISA / FBI",
          "title": "Iranian Government-Sponsored APT Actors Compromise Federal Network (AA22-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-320a",
          "date": "2022-11-16"
        }
      },
      {
        "cveId": "CVE-2021-26855",
        "firstExploited": "2021-04-01",
        "usage": "ProxyLogon exploited for Exchange access at targeted organisations in the Middle East and United States.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Iranian targeting of IT sector on the rise",
          "url": "https://www.microsoft.com/en-us/security/blog/2021/11/18/iranian-targeting-of-it-sector-on-the-rise/",
          "date": "2021-11-18"
        }
      },
      {
        "cveId": "CVE-2018-13379",
        "firstExploited": "2020-07-01",
        "usage": "FortiOS SSL VPN traversal used to harvest credentials from unpatched perimeter appliances.",
        "source": {
          "org": "CISA / FBI",
          "title": "Iran-Based Threat Actor Exploits VPN Vulnerabilities (AA20-259A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-259a",
          "date": "2020-09-15"
        }
      },
      {
        "cveId": "CVE-2019-11510",
        "firstExploited": "2020-06-01",
        "usage": "Pulse Secure arbitrary file read exploited to obtain plaintext VPN credentials.",
        "source": {
          "org": "CISA / FBI",
          "title": "Iran-Based Threat Actor Exploits VPN Vulnerabilities (AA20-259A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-259a",
          "date": "2020-09-15"
        }
      },
      {
        "cveId": "CVE-2021-34473",
        "firstExploited": "2021-09-01",
        "usage": "ProxyShell chain exploited for Exchange server access following public disclosure.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Iranian targeting of IT sector on the rise",
          "url": "https://www.microsoft.com/en-us/security/blog/2021/11/18/iranian-targeting-of-it-sector-on-the-rise/",
          "date": "2021-11-18"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "muddywater",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both Iranian state-nexus with overlapping regional targets; MOIS and IRGC respectively."
      },
      {
        "relatedActorId": "apt33",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both IRGC-aligned; APT33 focuses on aerospace and energy while APT35 pursues political and dissident targets."
      },
      {
        "relatedActorId": "cyberav3ngers",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both IRGC-linked; CyberAv3ngers operates against ICS under a hacktivist persona."
      }
    ],
    "reports": [
      {
        "org": "Google Threat Analysis Group",
        "title": "Iranian APT35 uses HYPERSCRAPE to steal email from victim accounts",
        "url": "https://blog.google/threat-analysis-group/iranian-apt-hyperscrape-tool/",
        "date": "2022-08-23"
      },
      {
        "org": "CISA and partners",
        "title": "AA22-320A: Iranian Government-Sponsored APT Actors Compromise Federal Network",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-320a",
        "date": "2022-11-16"
      },
      {
        "org": "Proofpoint",
        "title": "TA453 uses multi-persona impersonation to capitalize on FOMO",
        "url": "https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo",
        "date": "2022-10-25"
      },
      {
        "org": "Volexity",
        "title": "Charming Kitten Updates POWERSTAR with an InterPlanetary Twist",
        "url": "https://www.volexity.com/blog/2023/06/28/charming-kitten-updates-powerstar-with-an-interplanetary-twist/",
        "date": "2023-06-28"
      }
    ],
    "campaigns": [
      {
        "id": "apt35-election-2024",
        "actorId": "apt35",
        "name": "2024 U.S. Presidential Campaign Hack-and-Leak",
        "date": "2024-05-01",
        "endDate": "2024-09-27",
        "significance": "major",
        "targetSectors": [
          "Political Organizations",
          "Government",
          "Media & Journalism"
        ],
        "targetCountries": [
          "United States"
        ],
        "cveIds": [],
        "summary": "Compromise of accounts belonging to a U.S. presidential campaign, followed by attempts to distribute stolen material to media outlets and to individuals associated with the opposing campaign. Three IRGC-affiliated individuals were indicted in September 2024.",
        "sources": [
          {
            "org": "U.S. Department of Justice",
            "title": "Three IRGC Cyber Actors Indicted for Hack-and-Leak Operation",
            "url": "https://www.justice.gov/opa/pr/three-iranian-nationals-charged-hacking-and-leaking-campaign-designed-influence-2024-us",
            "date": "2024-09-27"
          }
        ]
      }
    ],
    "flag": "🇮🇷",
    "profile": "/apt/apt35/"
  }
}