Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Educated Manticore

Also known as: Charming Kitten, APT42, Mint Sandstorm, Magic Hound, APT35, TA453, Mint Sandstorm used email, Yellow Garuda, ITG18, tracked as, POWERSTAR, PowerLess, their PII, identity documents, GorjolEcho, CharmingCypress, including for debugging, code generation, MuddyWater, including telltale emojis, TA402, Parastoo, iKittens, NEWSCASTER, NewsBeef, Phosphorus, Group 83, Mango Sandstorm, TAG-135, OilRig

Description

Educated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting government, military, and academic sectors. The group employs spear-phishing tactics, utilizing custom backdoors like POWERLESS and phishing kits designed as SPAs to harvest credentials. Their operations have included impersonating credible figures to lure victims and using ISO images to initiate infection chains. Educated Manticore's activities are characterized by rapid domain setup and aggressive spear-phishing campaigns, particularly against Israeli individuals.

TTP Summary

Fake Social Media Account

Goals & Targeting

Targeted Sectors

Education
Defense
Media
Non profit
Government
Energy
Critical infrastructure
Maritime
Healthcare
Manufacturing
Transportation
Telecommunications
Aviation
Aerospace
Information technology
Oil gas
Financial services
Think tank
Food agriculture

Targeted Countries / Regions

IR
US
IL
RU
IQ
SA
UA
AE
CN
KP
TR
DE

AI Analysis

· 1 week ago

Executive Summary

Educated Manticore is an Iranian APT group linked to the Islamic Revolutionary Guard Corps (IRGC), primarily targeting government, military, and academic sectors through sophisticated espionage campaigns. The group employs spear-phishing tactics with custom backdoors like POWERLESS and phishing kits designed as SPAs to harvest credentials. Their operations are characterized by rapid domain setup and aggressive phishing campaigns, particularly against Israeli individuals.

Goals & Targeting

Educated Manticore's primary goal appears to be the collection of sensitive intelligence through espionage, targeting sectors critical to national security interests. The group specifically targets government, military, and academic institutions, often in regions adversarial to Iran, such as Israel. Their focus on these sectors suggests a strategic interest in political and military advantages gained through intelligence gathering.

Enhanced Description

Educated Manticore is a cyber-espionage group aligned with the Islamic Revolutionary Guard Corps (IRGC), targeting primarily government, military, and academic sectors. The group's modus operandi includes spear-phishing attacks using custom backdoors, such as POWERLESS, and phishing kits designed as System Preferences Applications (SPAs). These tools are used to deceive victims into revealing sensitive credentials. Educated Manticore has been observed impersonating credible figures to lure targets and using ISO images as infection vectors. The group's campaigns are notable for their rapid domain setup and aggressive phishing tactics, particularly against individuals in Israel. Their activities align with broader Iranian espionage objectives, likely aimed at gathering intelligence on adversaries such as Israel.

Key Capabilities

  • Spear-phishing campaigns with custom backdoors
  • Phishing kits designed as System Preferences Applications (SPAs)
  • Impersonation of credible figures for phishing
  • Use of ISO images as infection vectors
  • Rapid domain setup and fast-flux domains

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Credential Access
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1059.003
T1078.001
T1055
T1566.001
T1040

Software / Tooling

POWERLESS (custom backdoor)
Phishing Kits (SPA)
SPEAR phishing tools

Campaigns & Victims

Educated Manticore's campaigns are highly targeted, with a focus on specific individuals within the sectors they target. Their operations exhibit a rapid setup of domains and infrastructure, suggesting a high level of organizational capability. Notable past operations include extensive phishing campaigns against Israeli targets, utilizing ISO images for infection and credential harvesting. The group's persistence suggests continued operational activity in alignment with broader Iranian strategic interests.

IOC Patterns

  • Spear-phishing emails with attachments like POWERLESS backdoor
  • Custom phishing kits designed as System Preferences Applications (SPAs)
  • ISO image files used for infection vectors
  • Rapid setup of domains and fast-flux infrastructure

Recommended Actions

  • Implement multi-factor authentication (MFA) to mitigate credential theft risks.
  • Monitor for spear-phishing attempts with attachments like POWERLESS or SPAs.
  • Conduct regular security awareness training to identify phishing emails.
  • Inspect network traffic for domain generation algorithms and fast-flux patterns indicative of Educated Manticore campaigns.
  • Use threat intelligence feeds to block known malicious domains associated with this group.

Suggested Tags

APT
espionage
government-targeted
military-targeted

Confidence Assessment

The available data on Educated Manticore is credible and provides a clear picture of the group's targeting profile, TTPs, and capabilities. However, gaps remain in understanding their primary motivation beyond espionage and specific operational details such as exact campaign timelines and detailed attack chains.

ATT&CK Techniques

Persistence
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. research.checkpoint.com — Cited by web research for: POWERSTAR
  2. www.volexity.com — Cited by web research for: GorjolEcho
  3. www.recordedfuture.com — Cited by web research for: including for debugging
  4. research.checkpoint.com — Cited by web research for: Payload
  5. apt.etda.or.th — Cited by web research for: BASICSTAR
  6. www.trellix.com — Cited by web research for: curl

Intel Summary

1

Techniques

41

Tools

0

Campaigns

39

IOCs

0

Observed Data

1

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Government Targeting
espionage
government-targeted
military-targeted

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.