{"id":457,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2014<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Iran (IRGC)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Surveillance, Dissident Monitoring<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Fake social media personas, journalist and researcher targeting, phishing via WhatsApp and email<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">APT35, Phosphorus, Magic Hound, TA453, Ballistic Bobcat, Mint Sandstorm (partial)<\/div>\n  <\/div>\n<\/div>\n<p>Charming Kitten is one of Iran's most active and technically capable state-sponsored threat actor groups, attributed to the Islamic Revolutionary Guard Corps (IRGC) Intelligence Organisation. The group is distinguished by its extensive use of sophisticated fake online personas ,  often impersonating journalists, academics, think tank researchers, and policy experts ,  to conduct targeted social engineering campaigns against a diverse range of high-value targets including nuclear scientists, government officials, human rights advocates, and journalists covering Iranian affairs.<\/p>\n<p>Charming Kitten's credential harvesting operations are exceptionally patient and relationship-oriented: the group invests significant time in building trust through weeks or months of authentic-seeming correspondence before delivering a credential-harvesting link or malicious document. Their fake personas maintain active social media presences, publish research under stolen identities, and engage credibly in professional networks ,  a level of social engineering investment rarely seen outside of the most sophisticated nation-state operations.<\/p>\n<p>The group has targeted individuals associated with the Iran nuclear deal negotiations on multiple occasions, including think tank researchers, former US government officials, and international relations academics ,  suggesting a specific mandate to monitor and potentially influence nuclear diplomacy discourse. Charming Kitten has also aggressively targeted Israeli academics, military personnel, and government officials, as well as Iranian diaspora activists and opposition figures worldwide.<\/p>\n<p>A technically significant 2021 Charming Kitten operation involved the deployment of a novel iOS exploit delivered through malicious WhatsApp messages ,  a rare and sophisticated mobile targeting capability demonstrating the group's investment in expanding beyond traditional desktop phishing vectors. CISA has issued multiple alerts about Charming Kitten's ongoing campaigns against US critical infrastructure and government personnel, underscoring their sustained priority as a threat to Western security interests.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>Charming Kitten<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/charming-kitten\/","name":"Charming Kitten","slug":"charming-kitten","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}