All actors

Magic Hound

Also reported as Mint Sandstorm, TA453, Charming Kitten, Phosphorus, Newscaster and 25 other names. Linked to Iran by four sources.

Reports
283
Last reported
Known CVEs
146
Techniques in ATT&CK
78
Origin
Iran
ID
G0059
Merge evidence
45 alias matches

Reports per quarter

  1. 2012 Q3: 3 reports
  2. 2012 Q4: no reports
  3. 2013 Q1: no reports
  4. 2013 Q2: no reports
  5. 2013 Q3: no reports
  6. 2013 Q4: no reports
  7. 2014 Q1: no reports
  8. 2014 Q2: 3 reports
  9. 2014 Q3: no reports
  10. 2014 Q4: 1 report
  11. 2015 Q1: 1 report
  12. 2015 Q2: 1 report
  13. 2015 Q3: no reports
  14. 2015 Q4: 1 report
  15. 2016 Q1: no reports
  16. 2016 Q2: 6 reports
  17. 2016 Q3: no reports
  18. 2016 Q4: 2 reports
  19. 2017 Q1: 19 reports
  20. 2017 Q2: 1 report
  21. 2017 Q3: 2 reports
  22. 2017 Q4: 4 reports
  23. 2018 Q1: 2 reports
  24. 2018 Q2: 2 reports
  25. 2018 Q3: 2 reports
  26. 2018 Q4: 7 reports
  27. 2019 Q1: 8 reports
  28. 2019 Q2: 5 reports
  29. 2019 Q3: 10 reports
  30. 2019 Q4: 5 reports
  31. 2020 Q1: 6 reports
  32. 2020 Q2: 1 report
  33. 2020 Q3: 7 reports
  34. 2020 Q4: 5 reports
  35. 2021 Q1: 7 reports
  36. 2021 Q2: 4 reports
  37. 2021 Q3: 12 reports
  38. 2021 Q4: 9 reports
  39. 2022 Q1: 26 reports
  40. 2022 Q2: 14 reports
  41. 2022 Q3: 22 reports
  42. 2022 Q4: 4 reports
  43. 2023 Q1: 4 reports
  44. 2023 Q2: 9 reports
  45. 2023 Q3: 1 report
  46. 2023 Q4: 2 reports
  47. 2024 Q1: 4 reports
  48. 2024 Q2: 5 reports
  49. 2024 Q3: 4 reports
  50. 2024 Q4: 3 reports
  51. 2025 Q1: no reports
  52. 2025 Q2: 3 reports
  53. 2025 Q3: 1 report
  54. 2025 Q4: 1 report
  55. 2026 Q1: 4 reports
  56. 2026 Q2: 39 reports
  57. 2026 Q3: 1 report
Dated reports, 2012 Q3 to 2026 Q3.

Techniques seen in the last two years

Show all 48 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 61 techniques Show fewer

CVEs named in reports

Show all 146 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. StoneDrill (Malware Family)

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

Show all 283 reports Show fewer
  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  2. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

  3. LaZagne (Malware Family)

    date ORKL added it fromORKL

  4. Elfin Team

    date ORKL added it fromORKL

  5. Charming Kitten

    date ORKL added it fromORKL

  6. SpearSpecter

    Malpedia library date fromORKL

  7. COBALT ILLUSION Masquerades as Atlantic Council Employee

    date in the title fromORKL

  8. Drokbk Malware Uses GitHub as Dead Drop Resolver

    date in the title fromORKL

  9. Opsec Mistakes Reveal COBALT MIRAGE Threat Actors

    date in the title fromORKL

  10. APT42- Crooked Charms, Cons, and Compromises

    date in the title fromORKL

  11. Profiling DEV-0270- PHOSPHORUS’ ransomware operations

    date in the title fromORKL

  12. New Iranian APT data extraction tool

    date in the title fromORKL

  13. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  14. Old cat, new tricks, bad habits

    date in the CCS '25 data PricewaterhouseCoopers fromORKLCCS '25 data

  15. Charming Kitten (APT35)

    date in the title fromORKL

  16. COBALT MIRAGE Conducts Ransomware Operations in U.S.

    date in the title fromORKL

  17. APT_trends_report_Q2_2022_Securelist

    file creation date fromORKL

  18. yir-cyber-threats-report-download.pdf

    Malpedia library date fromORKL

  19. Social Engineering Remains Key Tradecraft for Iranian APTs

    date in the title fromORKL

  20. APT35 Automates Initial Access Using ProxyShell

    date in the CCS '25 data TheDFIRreport fromORKLCCS '25 data

  21. APT35 Automates Initial Access Using ProxyShell

    date in the title fromORKL

  22. Iranian-Aligned Threat Actor

    date in the CCS '25 data SentinelOne fromORKLCCS '25 data

  23. Exchange Exploit Leads to Domain Wide Ransomware

    date in the title fromORKL

  24. TM Follow-Up (TAG_APT35_14-10-21)

    date in the title fromORKL

  25. Countering threats from Iran (APT35)

    date in the title fromORKL

  26. Microsoft Digital Defense Report OCTOBER 2021

    file creation date fromORKL

  27. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  28. Operation SpoofedScholars- A Conversation with TA453

    date in the title fromORKL

  29. mtrends-2018.pdf

    file creation date fromORKL

  30. mtrends-2021

    file creation date fromORKL

  31. Charming Kitten’s Christmas Gift - Certfa Lab

    date in the CCS '25 data Certfa Lab fromORKLCCS '25 data

  32. Charming Kitten’s Christmas Gift

    date in the title fromORKL

  33. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  34. How we're tackling evolving online threats

    date in the title fromORKL

  35. FY20 Microsoft Digital Defense Report

    Malpedia library date fromORKL

  36. New cyberattacks targeting U.S. elections

    date in the title fromORKL

  37. The-Kittens-are-Back-in-Town-3

    Malpedia library date fromORKL

  38. New research exposes Iranian threat group operations

    Malpedia library date SecurityIntelligence fromORKLCCS '25 data

  39. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  40. Fake Interview- The New Activity of Charming Kitten

    date in the title fromORKL

  41. Shamoon 2012 Full Analysis

    Malpedia library date fromORKL

  42. Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs

    Malpedia library date Recorded Future fromORKLCCS '25 data

  43. The-Kittens-Are-Back-in-Town-2

    file creation date fromORKL

  44. The-Kittens-Are-Back-in-Town-Charming-Kitten-2019

    date in the CCS '25 data ClearSky fromORKLCCS '25 data

  45. APT_trends_report_Q2_2019_Securelist

    file creation date fromORKL

  46. APT trends report Q2 2019

    date in the title fromORKL

  47. Operation Newscaster

    date in the title fromORKL

  48. Operation Newscaster

    Malpedia library date fromORKL

  49. APT-Attacks-eng.pdf

    file creation date fromORKL

  50. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  51. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  52. rpt-mtrends-2019.pdf

    file creation date fromORKL

  53. New steps to protect customers from hacking

    date in the title fromORKL

  54. rpt-mtrends-2019

    file creation date fromORKL

  55. The Return of The Charming Kitten

    date in the CCS '25 data ClearSky fromORKLCCS '25 data

  56. The Return of The Charming Kitten

    date in the title fromORKL

  57. M-Trends Overview

    Malpedia library date Marco Rottigni fromORKL

  58. M-TRENDS2018

    file creation date FireEye fromORKL

  59. APT 35

    date in the CCS '25 data Council on Foreign Relations fromCCS '25 data

  60. Iran_Cyber_Final_Full_v2

    file creation date fromORKL

  61. Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists

    Malpedia library date Clearsky fromORKLCCS '25 data

  62. Advanced Persistent Threat Groups

    date in the title fromORKL

  63. Shamoon 2- Delivering Disttrack

    date in the title fromORKL

  64. From Shamoon to StoneDrill

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  65. additional-insights-shamoon2

    date in the CCS '25 data Arbor Networks fromORKLCCS '25 data

  66. Additional Insights on Shamoon2

    date in the CCS '25 data Arbor Networks fromORKLCCS '25 data

  67. Magic Hound Campaign Attacks Saudi Targets

    date in the title fromORKL

  68. Magic Hound Campaign Attacks Saudi Targets

    date in the CCS '25 data Palo Alto Networks fromORKLCCS '25 data

  69. Freezer Paper around Free Meat

    date in the title fromORKL

  70. Freezer Paper around Free Meat - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  71. Rocket Kitten: A Campaign With 9 Lives

    Malpedia library date Checkpoint fromORKL

  72. Global Threat Intel Report

    Malpedia library date Crowdstrike fromORKL

  73. Cylance_Operation_Cleaver_Report

    date in the CCS '25 data Cylance fromORKLCCS '25 data

  74. NEWSCASTER - An Iranian Threat Inside Social Media - iSIGHT Partners

    date in the CCS '25 data Mandiant fromORKLCCS '25 data

  75. NEWSCASTER: An Iranian Threat Within Social Networks - May 28, 2007

    Malpedia library date Mandiant fromORKLCCS '25 data

  76. The Shamoon Attacks | Symantec Connect Community

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.