🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
MINT SANDSTORM (APT35)

/actor/mint-sandstorm-apt35/  ·  0 intel reports

Year Established
2014
Attribution
Iran (IRGC)
Motivation
Espionage, Influence Operations, Journalist and Researcher Targeting
Modus Operandi (MO)
Spear-phishing, fake conference invitations, credential harvesting, targeting journalists and policy researchers
Primary Aliases
APT35, Charming Kitten (partial overlap), Phosphorus, ITG18, TA453, Yellow Garuda

Mint Sandstorm, tracked by many researchers as APT35 and previously associated with the "Charming Kitten" cluster, is an Iranian threat actor attributed to the Islamic Revolutionary Guard Corps (IRGC) with a primary mandate focused on intelligence collection against foreign policy researchers, journalists, academics, human rights activists, and government officials whose work intersects with Iranian affairs.

The group is renowned for its sophisticated and patient social engineering operations , building elaborate fake online personas of academics, journalists, conference organisers, and think tank researchers to establish trust with targets before delivering credential-harvesting links or malware-laden documents. Their "fake conference invitation" technique has been particularly effective: creating convincing invitations to non-existent or cloned versions of legitimate international policy conferences to capture credentials or install surveillance tools on researcher devices.

Mint Sandstorm has conducted extensive targeting of individuals with access to sensitive foreign policy discussions on Iran, including US State Department officials, former senior intelligence community members, nuclear negotiators, and journalists covering the Iranian government. The group has also aggressively targeted the personal email accounts and devices of Iranian diaspora members, opposition figures, and human rights defenders both inside and outside Iran.

In 2022, Microsoft revealed that Mint Sandstorm had been targeting former senior US government officials, nuclear scientists, and defence researchers , in some cases successfully compromising personal email accounts and exfiltrating sensitive communications. The IRGC's use of Mint Sandstorm for domestic and international surveillance underscores the dual internal repression and foreign intelligence collection mandate of Iranian state cyber operations.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Mint Sandstorm (APT35) requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles