{"id":492,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2014<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Iran (IRGC)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Influence Operations, Journalist and Researcher Targeting<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Spear-phishing, fake conference invitations, credential harvesting, targeting journalists and policy researchers<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">APT35, Charming Kitten (partial overlap), Phosphorus, ITG18, TA453, Yellow Garuda<\/div>\n  <\/div>\n<\/div>\n<p>Mint Sandstorm, tracked by many researchers as APT35 and previously associated with the \"Charming Kitten\" cluster, is an Iranian threat actor attributed to the Islamic Revolutionary Guard Corps (IRGC) with a primary mandate focused on intelligence collection against foreign policy researchers, journalists, academics, human rights activists, and government officials whose work intersects with Iranian affairs.<\/p>\n<p>The group is renowned for its sophisticated and patient social engineering operations ,  building elaborate fake online personas of academics, journalists, conference organisers, and think tank researchers to establish trust with targets before delivering credential-harvesting links or malware-laden documents. Their \"fake conference invitation\" technique has been particularly effective: creating convincing invitations to non-existent or cloned versions of legitimate international policy conferences to capture credentials or install surveillance tools on researcher devices.<\/p>\n<p>Mint Sandstorm has conducted extensive targeting of individuals with access to sensitive foreign policy discussions on Iran, including US State Department officials, former senior intelligence community members, nuclear negotiators, and journalists covering the Iranian government. The group has also aggressively targeted the personal email accounts and devices of Iranian diaspora members, opposition figures, and human rights defenders both inside and outside Iran.<\/p>\n<p>In 2022, Microsoft revealed that Mint Sandstorm had been targeting former senior US government officials, nuclear scientists, and defence researchers ,  in some cases successfully compromising personal email accounts and exfiltrating sensitive communications. The IRGC's use of Mint Sandstorm for domestic and international surveillance underscores the dual internal repression and foreign intelligence collection mandate of Iranian state cyber operations.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>Mint Sandstorm (APT35)<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/mint-sandstorm-apt35\/","name":"Mint Sandstorm (APT35)","slug":"mint-sandstorm-apt35","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}