Magic Hound
Also reported as Mint Sandstorm, TA453, Charming Kitten, Phosphorus, Newscaster and 25 other names. Linked to Iran by four sources.
Reports per quarter
Techniques seen in the last two years
- T1555.003 3 reports reports only
- T1566.002 3 reports in ATT&CK
- T1027 2 reports reports only
- T1041 2 reports reports only
- T1059.003 2 reports in ATT&CK
- T1190 2 reports in ATT&CK
- T1543.003 2 reports reports only
- T1566.001 2 reports reports only
- T1569.002 2 reports reports only
- T1587.001 2 reports reports only
Show all 48 techniques Show fewer
- T1588.002 2 reports in ATT&CK
- T1001 1 report reports only
- T1018 1 report in ATT&CK
- T1036.005 1 report in ATT&CK
- T1053 1 report reports only
- T1053.005 1 report in ATT&CK
- T1056 1 report reports only
- T1056.001 1 report in ATT&CK
- T1056.003 1 report reports only
- T1059 1 report reports only
- T1059.001 1 report in ATT&CK
- T1071 1 report in ATT&CK
- T1071.001 1 report in ATT&CK
- T1078 1 report reports only
- T1078.003 1 report reports only
- T1091 1 report reports only
- T1102 1 report reports only
- T1102.001 1 report reports only
- T1102.002 1 report in ATT&CK
- T1105 1 report in ATT&CK
- T1140 1 report reports only
- T1189 1 report in ATT&CK
- T1199 1 report reports only
- T1204 1 report reports only
- T1204.002 1 report in ATT&CK
- T1212 1 report reports only
- T1219 1 report reports only
- T1543 1 report reports only
- T1555 1 report reports only
- T1566 1 report reports only
- T1567 1 report in ATT&CK
- T1569 1 report reports only
- T1572 1 report in ATT&CK
- T1587 1 report reports only
- T1588 1 report reports only
- T1592 1 report reports only
- T1595 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
Show all 61 techniques Show fewer
- T1047
- T1049
- T1057
- T1059.005
- T1070.003
- T1070.004
- T1078.001
- T1078.002
- T1082
- T1083
- T1087.003
- T1090
- T1098.002
- T1098.007
- T1112
- T1113
- T1114
- T1114.001
- T1114.002
- T1136.001
- T1204.001
- T1218.011
- T1482
- T1486
- T1505.003
- T1547.001
- T1560.001
- T1564.003
- T1566.003
- T1570
- T1571
- T1573
- T1583.001
- T1583.006
- T1584.001
- T1585.001
- T1585.002
- T1586.002
- T1589
- T1589.001
- T1589.002
- T1590.005
- T1591.001
- T1592.002
- T1595.002
- T1598.003
- T1685
- T1685.001
- T1686.003
CVEs named in reports
- CVE-1999-0191
- CVE-1999-0262
- CVE-2010-0232 KEV
- CVE-2010-2861 KEV ransomware
- CVE-2011-1255
- CVE-2012-0158 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2013-0640 KEV
- CVE-2013-3893 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-1761 KEV
Show all 146 CVEs Show fewer
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6332 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-8651 KEV
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-11292 KEV
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-7921 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-1579
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-17100
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-5591 KEV ransomware
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12641 KEV
- CVE-2020-12812 KEV ransomware
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-1664
- CVE-2020-35730 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-20016 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-21974
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44428
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-20269 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2023-6895
- CVE-2024-1709 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21893 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 283 reports Show fewer
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Tortoiseshell, Imperial Kitten - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Tortoiseshell, Imperial Kitten - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
Cutting Kitten, TG-2889 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cutting Kitten, TG-2889 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor LaZagne (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Elfin Team
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Charming Kitten
-
Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
-
Rocket Kitten, Newscaster, NewsBeef - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Rocket Kitten, Newscaster, NewsBeef - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor SpearSpecter
-
Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350
-
Nation-state threat actor PHOSPHORUS refines tradecraft to attack high-value targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nation-state threat actor PHOSPHORUS refines tradecraft to attack high-value targets
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
COBALT ILLUSION Masquerades as Atlantic Council Employee
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COBALT ILLUSION Masquerades as Atlantic Council Employee
-
Drokbk Malware Uses GitHub as Dead Drop Resolver
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Drokbk Malware Uses GitHub as Dead Drop Resolver
-
Iran- State-Backed Hacking of Activists, Journalists, Politicians
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran- State-Backed Hacking of Activists, Journalists, Politicians
-
Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
-
Look What You Made Me Do- TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Look What You Made Me Do- TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Charming Kitten- -Can We Have A Meeting-- Important puzzle pieces of Charming Kitten's cyber espionage operations
-
APT42- Crooked Charms, Cons, and Compromises
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT42- Crooked Charms, Cons, and Compromises
-
Profiling DEV-0270- PHOSPHORUS’ ransomware operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Profiling DEV-0270- PHOSPHORUS’ ransomware operations
-
Analysis of APT35 Infrastructure Reveals Interest in Egyptian Shipping Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of APT35 Infrastructure Reveals Interest in Egyptian Shipping Companies
-
New Iranian APT data extraction tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Iranian APT data extraction tool
-
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Old cat, new tricks, bad habits
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Old cat, new tricks, bad habits
-
Old cat, new tricks, bad habits An analysis of Charming Kitten’s new tools and OPSEC errors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Old cat, new tricks, bad habits An analysis of Charming Kitten’s new tools and OPSEC errors
-
Above the Fold and in Your Inbox- Tracing State-Aligned Activity Targeting Journalists, Media
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Above the Fold and in Your Inbox- Tracing State-Aligned Activity Targeting Journalists, Media
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Charming Kitten (APT35)
-
Iranian Threat Actor Continues to Develop Mass Exploitation Tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Actor Continues to Develop Mass Exploitation Tools
-
COBALT MIRAGE Conducts Ransomware Operations in U.S.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COBALT MIRAGE Conducts Ransomware Operations in U.S.
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
Microsoft Obtains Court Order to Take Down Domains Used to Target Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Obtains Court Order to Take Down Domains Used to Target Ukraine
-
Social Engineering Remains Key Tradecraft for Iranian APTs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Social Engineering Remains Key Tradecraft for Iranian APTs
-
APT35 Automates Initial Access Using ProxyShell
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT35 Automates Initial Access Using ProxyShell
-
APT35 Automates Initial Access Using ProxyShell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 Automates Initial Access Using ProxyShell
-
Researchers Find New Evidence Linking Kwampirs Malware to Shamoon APT Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers Find New Evidence Linking Kwampirs Malware to Shamoon APT Hackers
-
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
-
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
-
MuddyWater targets Middle Eastern and Asian countries in phishing attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater targets Middle Eastern and Asian countries in phishing attacks
-
Exploitation of VMware Horizon Servers by TunnelVision Threat Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exploitation of VMware Horizon Servers by TunnelVision Threat Actor
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iranian-Aligned Threat Actor
-
Log4j2 In The Wild - Iranian-Aligned Threat Actor “TunnelVision” Actively Exploiting VMware Horizon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Log4j2 In The Wild - Iranian-Aligned Threat Actor “TunnelVision” Actively Exploiting VMware Horizon
-
PowerLess Trojan_ Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerLess Trojan_ Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage
-
Experts warn of a spike in APT35 activity and a possible link to Memento ransomware op
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Experts warn of a spike in APT35 activity and a possible link to Memento ransomware op
-
PowerLess Trojan- Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PowerLess Trojan- Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage
-
Cyberspies linked to Memento ransomware use new PowerShell malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberspies linked to Memento ransomware use new PowerShell malware
-
APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit
-
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
-
Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021
-
Exchange Exploit Leads to Domain Wide Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exchange Exploit Leads to Domain Wide Ransomware
-
TM Follow-Up (TAG_APT35_14-10-21)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TM Follow-Up (TAG_APT35_14-10-21)
-
Countering threats from Iran (APT35)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Countering threats from Iran (APT35)
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
ITG18 operational security errors plague Iranian threat group
The original link failed its last check. Original publisher Detailsfor ITG18 operational security errors plague Iranian threat group
-
ITG18- Operational Security Errors Continue to Plague Sizable Iranian Threat Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ITG18- Operational Security Errors Continue to Plague Sizable Iranian Threat Group
-
Operation SpoofedScholars- A Conversation with TA453
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation SpoofedScholars- A Conversation with TA453
-
The original link failed its last check. Original publisher Detailsfor mtrends-2018.pdf
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BadBlood_ TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns _ Proofpoint US
-
BadBlood- TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BadBlood- TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns
-
Charming Kitten’s Christmas Gift - Certfa Lab
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Charming Kitten’s Christmas Gift - Certfa Lab
-
Charming Kitten’s Christmas Gift
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Charming Kitten’s Christmas Gift
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Cyberattacks target international conference attendees (APT35-PHOSPHORUS)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberattacks target international conference attendees (APT35-PHOSPHORUS)
-
How we're tackling evolving online threats
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How we're tackling evolving online threats
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
New cyberattacks targeting U.S. elections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New cyberattacks targeting U.S. elections
-
The-Kittens-are-Back-in-Town-3
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The-Kittens-are-Back-in-Town-3
-
New Research Exposes Iranian Threat Group (APT35-ITG18) Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Research Exposes Iranian Threat Group (APT35-ITG18) Operations
-
New research exposes Iranian threat group operations
The original link failed its last check. Original publisher Detailsfor New research exposes Iranian threat group operations
-
Iranian Spies Accidentally Leaked Videos of Themselves Hacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Spies Accidentally Leaked Videos of Themselves Hacking
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
Fake Interview- The New Activity of Charming Kitten
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fake Interview- The New Activity of Charming Kitten
-
Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
-
The original link failed its last check. Original publisher Detailsfor Shamoon 2012 Full Analysis
-
Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Kittens Are Back in Town 2 - Charming Kitten Campaign Keeps Going on, Using New Impersonation Methods - ClearSky Cyber Security
-
The-Kittens-Are-Back-in-Town-2
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The-Kittens-Are-Back-in-Town-2
-
The-Kittens-Are-Back-in-Town-Charming-Kitten-2019
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The-Kittens-Are-Back-in-Town-Charming-Kitten-2019
-
APT_trends_report_Q2_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2019_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2019
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Newscaster
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Operation Newscaster
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Actor Amasses Large Cyber Operations Infrastructure Network to Target Saudi Organizations
-
The original link failed its last check. Original publisher Detailsfor APT-Attacks-eng.pdf
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
New steps to protect customers from hacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New steps to protect customers from hacking
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
The Return of The Charming Kitten
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Return of The Charming Kitten
-
The Return of The Charming Kitten
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Return of The Charming Kitten
-
Persian Stalker pillages Iranian users of Instagram and Telegram
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Persian Stalker pillages Iranian users of Instagram and Telegram
-
Iranian APT Charming Kitten impersonates ClearSky, the security firm that uncovered its campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian APT Charming Kitten impersonates ClearSky, the security firm that uncovered its campaigns
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iran_Cyber_Final_Full_v2
-
Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
With Fake News And Femmes Fatales, Iran's Spies Learn To Love Facebook
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor With Fake News And Femmes Fatales, Iran's Spies Learn To Love Facebook
-
Shamoon 2- Delivering Disttrack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shamoon 2- Delivering Disttrack
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor From Shamoon to StoneDrill
-
Magic Hound Campaign Attacks Saudi Targets - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Magic Hound Campaign Attacks Saudi Targets - Palo Alto Networks Blog
-
Shamoon- Multi-staged destructive attacks limited to specific targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shamoon- Multi-staged destructive attacks limited to specific targets
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor additional-insights-shamoon2
-
Additional Insights on Shamoon2
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Additional Insights on Shamoon2
-
Iranian hackers behind the Magic Hound campaign linked to Shamoon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian hackers behind the Magic Hound campaign linked to Shamoon
-
Magic Hound Campaign Attacks Saudi Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Magic Hound Campaign Attacks Saudi Targets
-
Magic Hound Campaign Attacks Saudi Targets
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Magic Hound Campaign Attacks Saudi Targets
-
iKittens- Iranian Actor Resurfaces with Malware for Mac (MacDownloader)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor iKittens- Iranian Actor Resurfaces with Malware for Mac (MacDownloader)
-
Greenbug cyberespionage group targeting Middle East, possible links to Shamoon
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Greenbug cyberespionage group targeting Middle East, possible links to Shamoon
-
Freezer Paper around Free Meat (Repackaging Open Source BeEF for Tracking and More)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Freezer Paper around Free Meat (Repackaging Open Source BeEF for Tracking and More)
-
Freezer Paper around Free Meat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Freezer Paper around Free Meat
-
Freezer Paper around Free Meat - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Freezer Paper around Free Meat - Securelist
-
Rocket Kitten: A Campaign With 9 Lives
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Rocket Kitten: A Campaign With 9 Lives
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Cylance_Operation_Cleaver_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cylance_Operation_Cleaver_Report
-
NEWSCASTER - An Iranian Threat Inside Social Media - iSIGHT Partners
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor NEWSCASTER - An Iranian Threat Inside Social Media - iSIGHT Partners
-
NEWSCASTER: An Iranian Threat Within Social Networks - May 28, 2007
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor NEWSCASTER: An Iranian Threat Within Social Networks - May 28, 2007
-
Iranian Hackers Targeted US Officials in Elaborate Social Media Attack Operation _ SecurityWeek
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Hackers Targeted US Officials in Elaborate Social Media Attack Operation _ SecurityWeek
-
The Shamoon Attacks | Symantec Connect Community
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor The Shamoon Attacks | Symantec Connect Community
Newest first. Details opens the report in Explore.