Skip to content
IranState-SponsoredActiveMITRE G0059Malpedia ↗

APT35

IRGC-linked social engineering specialists. Will spend weeks impersonating a journalist or academic before ever sending a link.

ATTRIBUTED TOIran › Islamic Revolutionary Guard Corps (IRGC) › IRGC-affiliated contractors, including Emennet Pasargad and Mahak Rayan Afraz

Open MITRE Navigator layer ↗Download profile JSON
Active
2013–present
Motivation
Espionage, Information Operations
Aliases
11
Exploited CVEs
5
ATT&CK techniques
11
Cited sources
12

Overview

APT35 — most commonly known as Charming Kitten — invests more effort in human manipulation than almost any other state actor, and it shows in the results.

Operators build durable fictitious personas: journalists from real outlets, conference organisers, researchers at recognisable think tanks. They make contact over weeks, sometimes months. They hold genuine conversations about the target's actual work. Several documented operations used multiple coordinated personas who referenced each other to manufacture credibility, and at least one used a fake video conference in which the target believed they were speaking with a real institution.

Only after trust is established does the malicious link appear — usually a credential-harvesting page for a webmail or SSO service, delivered via a real-time proxy that captures the session token and defeats MFA.

The targeting is politically specific and often personal: Iranian dissidents and journalists in exile, academics researching Iran, nuclear policy specialists, government officials, and — notably — the families of targets, approached as a route to the primary. During the 2020 and 2024 U.S. election cycles the group targeted campaign staff, and in 2024 the Department of Justice indicted three IRGC-affiliated individuals over a hack-and-leak operation against a U.S. presidential campaign.

The 2019 Microsoft disclosure of "Phosphorus" targeting a U.S. presidential campaign, and the 2022 CISA advisory on the group's Log4Shell exploitation of unpatched VMware Horizon servers, mark the two poles of its capability: sophisticated social engineering at the front, opportunistic mass exploitation when a good bug appears.

Attribution

Down to the named unit where public evidence supports it.

IranIslamic Revolutionary Guard Corps (IRGC)IRGC-affiliated contractors, including Emennet Pasargad and Mahak Rayan AfrazHigh confidence

Assessed as operating on behalf of the IRGC. The U.S. Department of Justice indicted three IRGC-affiliated individuals in September 2024 over a hack-and-leak operation against a U.S. presidential campaign, and the Treasury has sanctioned multiple IRGC-linked front companies for related activity, including Emennet Pasargad. Attribution to the IRGC rather than the MOIS is based on targeting patterns, contractor relationships, and U.S. government statements, though the boundaries between Iranian contractor clusters are less clearly established than for Russian or Chinese services.

Attributing sources

Cross-vendor naming crosswalk

11 designators across 10 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • Magic Hound

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Mint SandstormFormerly PHOSPHORUS
  • PHOSPHORUSRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Charming Kitten

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT35

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • COBALT ILLUSION

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Charming Serpens

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • ITG18partialIBM X-Force designator, widely cross-referenced

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Trend Micro

index ↗
  • Earth VetalapartialPartial overlap with tracked activity

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

Proofpoint

index ↗
  • TA453

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • Charming Kitten

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesIsraelUnited KingdomSaudi ArabiaIranGermanyFranceUnited Arab Emirates

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

POWERSTAR / GorjolEchobackdoor

PowerShell backdoor delivered after extended rapport-building, with validation logic that decrypts only on the intended host.

HYPERSCRAPEutility

Mailbox exfiltration tool that downloads messages and restores their unread status to conceal the theft.

BellaCiaobackdoor

Personalised dropper compiled per-victim, with the target's organisation encoded in the binary and DNS-based activation.

PowerLessbackdoor

PowerShell backdoor with keylogging, browser credential theft, and screenshot capability.

Shared, commodity & living-off-the-land

Evilginx-style AiTM proxiesframework

Real-time credential proxies capturing session cookies to defeat MFA.

Fake video conferencingutility

Staged online meetings used to build credibility before delivering a malicious link.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT35
CVE-2021-44228KEVransomware10.01 Feb 2022Log4Shell exploited against an unpatched VMware Horizon server at a U.S. federal civilian agency, leading to XMRig cryptomining, credential harvesting, and lateral movement — documented in detail by CISA.SRCCISA / FBI
CVE-2021-34473KEVransomware9.81 Sep 2021ProxyShell chain exploited for Exchange server access following public disclosure.SRCMicrosoft Threat Intelligence
CVE-2021-26855KEVransomware9.81 Apr 2021ProxyLogon exploited for Exchange access at targeted organisations in the Middle East and United States.SRCMicrosoft Threat Intelligence
CVE-2018-13379KEVransomware9.81 Jul 2020FortiOS SSL VPN traversal used to harvest credentials from unpatched perimeter appliances.SRCCISA / FBI
CVE-2019-11510KEVransomware10.01 Jun 2020Pulse Secure arbitrary file read exploited to obtain plaintext VPN credentials.SRCCISA / FBI

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

8 stages · 11 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
11 techniques across 8 tactics · 6 with actor-specific notes

Reconnaissance

1

Resource Development

2

Initial Access

2

Credential Access

2

Collection

1

Campaign timeline

  1. 2024 U.S. Presidential Campaign Hack-and-Leak

    Compromise of accounts belonging to a U.S. presidential campaign, followed by attempts to distribute stolen material to media outlets and to individuals associated with the opposing campaign. Three IRGC-affiliated individuals were indicted in September 2024.

    Political OrganizationsGovernmentMedia & Journalism

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.