Also known as: Charming Kitten, APT42, Mint Sandstorm, Magic Hound, APT35, TA453, Mint Sandstorm used email, Yellow Garuda, ITG18, tracked as, POWERSTAR, PowerLess, their PII, identity documents, GorjolEcho, CharmingCypress, including for debugging, code generation, MuddyWater, including telltale emojis, TA402, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, Group 83, Mango Sandstorm, TAG-135, OilRig
Educated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting government, military, and academic sectors. The group employs spear-phishing tactics, utilizing custom backdoors like POWERLESS and phishing kits designed as SPAs to harvest credentials. Their operations have included impersonating credible figures to lure victims and using ISO images to initiate infection chains. Educated Manticore's activities are characterized by rapid domain setup and aggressive spear-phishing campaigns, particularly against Israeli individuals.
Fake Social Media Account
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Educated Manticore is an Iranian APT group linked to the Islamic Revolutionary Guard Corps (IRGC), primarily targeting government, military, and academic sectors through sophisticated espionage campaigns. The group employs spear-phishing tactics with custom backdoors like POWERLESS and phishing kits designed as SPAs to harvest credentials. Their operations are characterized by rapid domain setup and aggressive phishing campaigns, particularly against Israeli individuals.
Goals & Targeting
Educated Manticore's primary goal appears to be the collection of sensitive intelligence through espionage, targeting sectors critical to national security interests. The group specifically targets government, military, and academic institutions, often in regions adversarial to Iran, such as Israel. Their focus on these sectors suggests a strategic interest in political and military advantages gained through intelligence gathering.
Enhanced Description
Educated Manticore is a cyber-espionage group aligned with the Islamic Revolutionary Guard Corps (IRGC), targeting primarily government, military, and academic sectors. The group's modus operandi includes spear-phishing attacks using custom backdoors, such as POWERLESS, and phishing kits designed as System Preferences Applications (SPAs). These tools are used to deceive victims into revealing sensitive credentials. Educated Manticore has been observed impersonating credible figures to lure targets and using ISO images as infection vectors. The group's campaigns are notable for their rapid domain setup and aggressive phishing tactics, particularly against individuals in Israel. Their activities align with broader Iranian espionage objectives, likely aimed at gathering intelligence on adversaries such as Israel.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Educated Manticore's campaigns are highly targeted, with a focus on specific individuals within the sectors they target. Their operations exhibit a rapid setup of domains and infrastructure, suggesting a high level of organizational capability. Notable past operations include extensive phishing campaigns against Israeli targets, utilizing ISO images for infection and credential harvesting. The group's persistence suggests continued operational activity in alignment with broader Iranian strategic interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on Educated Manticore is credible and provides a clear picture of the group's targeting profile, TTPs, and capabilities. However, gaps remain in understanding their primary motivation beyond espionage and specific operational details such as exact campaign timelines and detailed attack chains.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
41
Tools
0
Campaigns
39
IOCs
0
Observed Data
1
Tactics