> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
MINT SANDSTORM (APT35)
/actor/mint-sandstorm-apt35/ · 0 intel reports
Mint Sandstorm, tracked by many researchers as APT35 and previously associated with the "Charming Kitten" cluster, is an Iranian threat actor attributed to the Islamic Revolutionary Guard Corps (IRGC) with a primary mandate focused on intelligence collection against foreign policy researchers, journalists, academics, human rights activists, and government officials whose work intersects with Iranian affairs.
The group is renowned for its sophisticated and patient social engineering operations , building elaborate fake online personas of academics, journalists, conference organisers, and think tank researchers to establish trust with targets before delivering credential-harvesting links or malware-laden documents. Their "fake conference invitation" technique has been particularly effective: creating convincing invitations to non-existent or cloned versions of legitimate international policy conferences to capture credentials or install surveillance tools on researcher devices.
Mint Sandstorm has conducted extensive targeting of individuals with access to sensitive foreign policy discussions on Iran, including US State Department officials, former senior intelligence community members, nuclear negotiators, and journalists covering the Iranian government. The group has also aggressively targeted the personal email accounts and devices of Iranian diaspora members, opposition figures, and human rights defenders both inside and outside Iran.
In 2022, Microsoft revealed that Mint Sandstorm had been targeting former senior US government officials, nuclear scientists, and defence researchers , in some cases successfully compromising personal email accounts and exfiltrating sensitive communications. The IRGC's use of Mint Sandstorm for domestic and international surveillance underscores the dual internal repression and foreign intelligence collection mandate of Iranian state cyber operations.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Mint Sandstorm (APT35) requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.