Charming Kitten (other aliases include APT35 (by
Mandiant
Mandiant is an American cybersecurity firm and a subsidiary of Google. It rose to prominence in February 2013 when it released a report directly implicating China in cyber espionage. In December 2013, Mandiant was acquired by FireEye for $1 b ...
), Phosphorus (by
Microsoft
Microsoft Corporation is an American multinational corporation, multinational technology company, technology corporation producing Software, computer software, consumer electronics, personal computers, and related services headquartered at th ...
), Ajax Security (by
FireEye
Trellix (formerly FireEye and McAfee Enterprise) is a privately held cybersecurity company founded in 2022. It has been involved in the detection and prevention of major cyber attacks.
It provides hardware, software, and services to investigat ...
), NewsBeef (by
Kaspersky,)) is an
Iranian government
The Government of the Islamic Republic of Iran ( fa, نظام جمهوری اسلامی ایران, Neẓām-e jomhūrī-e eslāmi-e Irān, known simply as ''Neẓām'' ( fa, نظام, lit=the system) among its supporters) is the ruling state a ...
cyberwarfare
Cyberwarfare is the use of cyber attacks against an enemy state, causing comparable harm to actual warfare and/or disrupting vital computer systems. Some intended outcomes could be espionage, sabotage, propaganda, manipulation or economic war ...
group, described by several companies and government officials as an
advanced persistent threat
An advanced persistent threat (APT) is a stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period. In recent times, the term m ...
.
On December 15, 2017, the group was designated by
FireEye
Trellix (formerly FireEye and McAfee Enterprise) is a privately held cybersecurity company founded in 2022. It has been involved in the detection and prevention of major cyber attacks.
It provides hardware, software, and services to investigat ...
as a
nation state
A nation state is a political unit where the state and nation are congruent. It is a more precise concept than "country", since a country does not need to have a predominant ethnic group.
A nation, in the sense of a common ethnicity, may i ...
-based advanced persistent threat, regardless of the lack of its sophistication. Research conducted by FireEye in 2018 suggested that APT35 may be expanding their
malware
Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, de ...
capabilities and intrusion campaigns.
The group has since been known to use
phishing
Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious softwar ...
to impersonate company websites, as well as fake accounts and fake
DNS domain
The Domain Name System (DNS) is a hierarchical and distributed naming system for computers, services, and other resources in the Internet or other Internet Protocol (IP) networks. It associates various information with domain names assigned t ...
s to phish users'
password
A password, sometimes called a passcode (for example in Apple devices), is secret data, typically a string of characters, usually used to confirm a user's identity. Traditionally, passwords were expected to be memorized, but the large number of ...
s.
History
Witt Defection (Early 2013)
In 2013, former United States Air Force technical sergeant and military intelligence defense contractor
Monica Witt defected to Iran knowing she might incur criminal charges by the United Stages for doing so. Her giving of intelligence to the government of Iran later caused Operation Saffron Rose, a cyberwarfare operation that targeted US military contractors.
HBO cyberattack (2017)
In 2017, following a cyberattack on
HBO
Home Box Office (HBO) is an American premium television network, which is the flagship property of namesake parent subsidiary Home Box Office, Inc., itself a unit owned by Warner Bros. Discovery. The overall Home Box Office business unit is ba ...
, a large-scale joint investigation was launched on the grounds that confidential information was being leaked. A conditional statement by a hacker going by alias Sokoote Vahshat (
Persian
Persian may refer to:
* People and things from Iran, historically called ''Persia'' in the English language
** Persians, the majority ethnic group in Iran, not to be conflated with the Iranic peoples
** Persian language, an Iranian language of the ...
سکوت وحشت lit. ''Silence of Fear'') said that if money was not paid, scripts of television episodes, including episodes of ''
Game of Thrones
''Game of Thrones'' is an American fantasy drama television series created by David Benioff and D. B. Weiss for HBO. It is an adaptation of ''A Song of Ice and Fire'', a series of fantasy novels by George R. R. Martin, the firs ...
'', would be leaked. The hack caused a leak of 1.5 terabytes of data, some of which was shows and episodes that had not been broadcast at the time. HBO has since stated that it would take steps to make sure that they would not be breached again.
Behzad Mesri was subsequently indicted for the hack. He has since been alleged to be part of the operation unit that had leaked confidential information.
According to Certfa, Charming Kitten had targeted US officials involved with the 2015
Iran Nuclear Deal
The Joint Comprehensive Plan of Action (JCPOA; fa, برنامه جامع اقدام مشترک , barnāmeye jāme'e eqdāme moshtarak (, ''BARJAM'')), commonly known as the Iran nuclear deal or Iran deal, is an agreement on the Iranian nuclear ...
. The Iranian government denied any involvement.
Second Indictment (2019)
A
federal grand jury
Grand juries in the United States are groups of citizens empowered by United States federal or state law to conduct legal proceedings, chiefly investigating potential criminal conduct and determining whether criminal charges should be brought. ...
in the
United States District Court for the District of Columbia
The United States District Court for the District of Columbia (in case citations, D.D.C.) is a United States district court, federal district court in the District of Columbia. It also occasionally handles (jointly with the United States Dist ...
indicted Witt on espionage charges (speciifcally "conspiracy to deliver and delivering national defense information to representatives of the Iranian government"). The indictment was unsealed on February 19, 2019. In the same indictment, four Iranian nationals—Mojtaba Masoumpour, Behzad Mesri, Hossein Parvar and Mohamad Paryar—were charged with conspiracy, attempting to commit computer intrusion, and aggravated identity theft, for a campaign in 2014 and 2015 that sought to compromise the data of Witt's former co-workers.
In March 2019,
Microsoft
Microsoft Corporation is an American multinational corporation, multinational technology company, technology corporation producing Software, computer software, consumer electronics, personal computers, and related services headquartered at th ...
took ownership of 99 DNS domains owned by the Iranian government-sponsored hackers, in a move intended to decrease the risk of spear-phishing and other cyberattacks.
2020 Election interference attempts (2019)
According to Microsoft, in a 30-day period between August and September 2019, Charming Kitten made 2,700 attempts to gain information regarding targeted email accounts. This resulted in 241 attacks and 4 compromised accounts. Although the initiative was deemed to have been aimed at a United States presidential campaign, none of the compromised accounts were related to the election.
Microsoft did not reveal who specifically was targeted, but a subsequent report by Reuters claimed it was Donald Trump's re-election campaign. This assertion is corroborated by the fact that only the Trump campaign used Microsoft Outlook as an email client.
Iran denied any involvement in election meddling, with the Iranian Foreign Minister
Mohammad Javad Zarif
Mohammad Javad Zarif Khansari ( fa, محمدجواد ظریف خوانساری, Mohammad-Javād Zarīf Khānsāri ; ; born 8 January 1960) is an Iranian career diplomat and academic. He was the foreign minister of Iran from 2013 until 2021 in ...
stating "We don’t have a preference in your election
he United States
He or HE may refer to:
Language
* He (pronoun), an English pronoun
* He (kana), the romanization of the Japanese kana へ
* He (letter), the fifth letter of many Semitic alphabets
* He (Cyrillic), a letter of the Cyrillic script called ''He'' ...
to intervene in that election," and "We don’t interfere in the internal affairs of another country," in an interview on NBC's "Meet The Press".
Cybersecurity experts at Microsoft and third-party firms such as ClearSky Cyber Security maintain that Iran, specifically Charming Kitten, was behind the attempted interference, however. In October 2019, ClearSky released a report supporting Microsoft's initial conclusion. In the report, details about the cyberattack were compared to those of previous attacks known to originate from Charming Kitten. The following similarities were found:
* Similar victim profiles. Those targeted fell into similar categories. They were all people of interest to Iran in the fields of academia, journalism, human rights activism, and political opposition.
* Time overlap. Verified Charming Kitten activity was ramping up within the same timeframe that the election interference attempts were made.
* Consistent attack vectors. The methods of attack were similar, with the malicious agents relying on spear-phishing via SMS texts.
2022 HYPERSCRAPE, APT data extraction tool (2021)
On August 23, 2022, a Google Threat Analysis Group (TAG) blog post revealed a new tool developed by Charming Kitten to steal data from well-known email providers (i.e. Google, Yahoo!, and Microsoft).
[ ] This tool needs the target's credentials to create a session on its behalf. It acts in such a way that using old-style mail services looks normal to the server and downloads the victim's emails, and does some changes to hide its fingerprint.
Per the report, the tool is developed on the windows platform but not for the victim's machine. It uses both command line and GUI to enter credentials or other required resources like cookies.
See also
*
Sony Pictures hack
On November 24, 2014, a hacker group identifying itself as "Guardians of Peace" leaked a release of confidential data from the film studio Sony Pictures Entertainment (SPE). The data included personal information about Sony Pictures employees a ...
*
Monica Witt
References
{{Iran–United States relations
Iranian advanced persistent threat groups
Iran–United States relations
Cyberwarfare