Also known as: TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm, Parastoo, iKittens, NewsBeef, Group 83, Timberworm, MAGNALLIUM, Elfin, Refined Kitten, Holmium, APT33, Imperial Kitten, G0058, CharmingCypress, TEMP.Beanie, Operation Woolen Goldfish, Operation Woolen-Goldfish, Thamar Reservoir, Smoke Sandstorm, BOHRIUM, Newscaster Team, Magic Hound, G0059, TunnelVision, COBALT MIRAGE, Agent Serpens, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, DEV-0228, Flying Kitten, Saffron Rose, Ajax Security Team, Rocket Kitten, Group 26, SaffronRose, AjaxSecurityTeam, Sayad
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Secureworks COBALT ILLUSION Threat Profile)(Citation: Proofpoint TA453 July2021)
Fake Social Media Account
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Magic Hound, an Iranian-sponsored threat group, conducts long-term cyber espionage operations targeting government, transportation, energy, and defense sectors in the US and SA. They utilize complex social engineering campaigns, including fake social media accounts, to compromise high-value targets. Their primary motivation is espionage, likely on behalf of the Islamic Revolutionary Guard Corps.
Goals & Targeting
Magic Hound's primary objective is to conduct cyber espionage operations on behalf of the Islamic Revolutionary Guard Corps, targeting high-value individuals and organizations in the government, transportation, energy, and defense sectors. Their targeting profile suggests a focus on extracting sensitive information, likely for strategic or tactical gain. The group's activities are often tailored to support Iranian national interests, and their operations have been linked to various state-sponsored initiatives.
Enhanced Description
Magic Hound's operations have been documented by various security researchers and firms, including FireEye, ClearSky, and Certfa. These reports provide valuable insights into the group's TTPs, motivations, and target profiles, and underscore the importance of vigilance and proactive defense against such sophisticated threat actors. As the threat landscape continues to evolve, it is essential to monitor Magic Hound's activities and adapt defensive strategies to counter their increasingly complex and targeted operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Magic Hound's campaigns are characterized by their long-term, resource-intensive nature, often spanning several months or even years. Their operations typically involve a combination of social engineering tactics, including fake social media accounts, email spoofing, and phishing, to establish an initial foothold within the target network. The group's activities have been linked to various high-profile operations, including the targeting of government officials, academics, and journalists, and have demonstrated an ability to adapt their tactics to evade detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on Magic Hound provides a moderate to high level of confidence in their TTPs, motivations, and target profiles. However, there are gaps in the data regarding the group's full capabilities, the extent of their operations, and the specific tools and techniques used in their campaigns. Further research and monitoring are necessary to fill these gaps and provide a more comprehensive understanding of this sophisticated threat actor.
No observed data linked yet.
No IOCs linked yet.
78
Techniques
26
Tools
3
Campaigns
0
IOCs
0
Observed Data
14
Tactics