APT35
Summary
APT35, also known as Charming Kitten, is a threat actor group believed to be linked to Iran. It is known for conducting cyber espionage and information theft campaigns targeting government, military, academic, and private sector organizations worldwide. APT35 primarily employs spear-phishing, credential harvesting, and malware deployment to gain unauthorized access and maintain persistence within targeted networks.
Key Characteristics
- Use of spear-phishing emails with social engineering to deliver malicious payloads or credential harvesting links.
- Deployment of custom malware families such as “Charming Kitten” and “Phosphorus” to conduct espionage activities.
- Targeting of individuals involved in political, diplomatic, and security-related fields, often focusing on Middle Eastern and Western countries.
- Utilization of compromised websites and fake social media profiles to lure victims and establish communication channels.
- Capability to conduct long-term campaigns with stealthy persistence mechanisms to avoid detection.
Defensive Controls
- Implement multi-factor authentication (MFA) to reduce the risk of credential compromise.
- Conduct regular security awareness training focusing on spear-phishing and social engineering tactics.
- Deploy advanced email filtering and anti-phishing technologies to detect and block malicious messages.
- Maintain up-to-date endpoint protection solutions capable of detecting custom malware variants.
- Monitor network traffic and logs for unusual activity indicative of lateral movement or data exfiltration.
Related Security Solutions
Security solutions relevant to defending against APT35 include advanced threat protection platforms, endpoint detection and response (EDR) tools, secure email gateways, identity and access management (IAM) systems with MFA capabilities, and threat intelligence services that provide timely indicators of compromise related to APT35 activities.