Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Magic Hound

Also known as: TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm, Parastoo, iKittens, NewsBeef, Group 83, Timberworm, MAGNALLIUM, Elfin, Refined Kitten, Holmium, APT33, Imperial Kitten, G0058, CharmingCypress, TEMP.Beanie, Operation Woolen Goldfish, Operation Woolen-Goldfish, Thamar Reservoir, Smoke Sandstorm, BOHRIUM, Newscaster Team, Magic Hound, G0059, TunnelVision, COBALT MIRAGE, Agent Serpens, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, DEV-0228, Flying Kitten, Saffron Rose, Ajax Security Team, Rocket Kitten, Group 26, SaffronRose, AjaxSecurityTeam, Sayad

Description

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Secureworks COBALT ILLUSION Threat Profile)(Citation: Proofpoint TA453 July2021)

TTP Summary

Fake Social Media Account

Goals & Targeting

Targeted Sectors

Government
Transportation
Energy
Defense
Financial services
Healthcare
Pharmaceutical
Telecommunications
Media
Non profit
Legal services
Education
Research
Critical infrastructure

Targeted Countries / Regions

US
SA
IL
IR

AI Analysis

· 2 months ago

Executive Summary

Magic Hound, an Iranian-sponsored threat group, conducts long-term cyber espionage operations targeting government, transportation, energy, and defense sectors in the US and SA. They utilize complex social engineering campaigns, including fake social media accounts, to compromise high-value targets. Their primary motivation is espionage, likely on behalf of the Islamic Revolutionary Guard Corps.

Goals & Targeting

Magic Hound's primary objective is to conduct cyber espionage operations on behalf of the Islamic Revolutionary Guard Corps, targeting high-value individuals and organizations in the government, transportation, energy, and defense sectors. Their targeting profile suggests a focus on extracting sensitive information, likely for strategic or tactical gain. The group's activities are often tailored to support Iranian national interests, and their operations have been linked to various state-sponsored initiatives.

Enhanced Description

Magic Hound's operations have been documented by various security researchers and firms, including FireEye, ClearSky, and Certfa. These reports provide valuable insights into the group's TTPs, motivations, and target profiles, and underscore the importance of vigilance and proactive defense against such sophisticated threat actors. As the threat landscape continues to evolve, it is essential to monitor Magic Hound's activities and adapt defensive strategies to counter their increasingly complex and targeted operations.

Key Capabilities

  • Social engineering
  • Fake social media account creation
  • Email spoofing
  • Phishing
  • Credential harvesting
  • Network exploitation

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204
T1550
T1595

Software / Tooling

Custom malware
Phishing kits
Social engineering frameworks
C2 frameworks

Campaigns & Victims

Magic Hound's campaigns are characterized by their long-term, resource-intensive nature, often spanning several months or even years. Their operations typically involve a combination of social engineering tactics, including fake social media accounts, email spoofing, and phishing, to establish an initial foothold within the target network. The group's activities have been linked to various high-profile operations, including the targeting of government officials, academics, and journalists, and have demonstrated an ability to adapt their tactics to evade detection.

IOC Patterns

  • Spear-phishing with fake social media accounts
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Email spoofing with typo-squatted domain names

Recommended Actions

  • Implement robust social media account verification processes
  • Conduct regular security awareness training for employees
  • Utilize advanced email filtering solutions to detect spoofed emails
  • Monitor network traffic for suspicious C2 activity
  • Implement a threat intelligence-driven defense strategy

Suggested Tags

APT
Espionage
State-sponsored
Social engineering
Phishing

Confidence Assessment

The available data on Magic Hound provides a moderate to high level of confidence in their TTPs, motivations, and target profiles. However, there are gaps in the data regarding the group's full capabilities, the extent of their operations, and the specific tools and techniques used in their campaigns. Further research and monitoring are necessary to fill these gaps and provide a more comprehensive understanding of this sophisticated threat actor.

ATT&CK Techniques

Collection
7 techniques
Command & Control
8 techniques
Defense impairment
4 techniques
Discovery
12 techniques
Execution
7 techniques
Initial Access
4 techniques
Persistence
5 techniques
Reconnaissance
8 techniques
Resource Development
7 techniques
Stealth
11 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Microsoft Phosphorus Mar 2019 — Burt, T. (2019, March 27). New steps to protect customers from hacking. Retrieved May 27, 2020.
  2. Microsoft Phosphorus Oct 2020 — Burt, T. (2020, October 28). Cyberattacks target international conference attendees. Retrieved March 8, 2021.
  3. Certfa Charming Kitten January 2021 — Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021.
  4. Check Point APT35 CharmPower January 2022 — Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.
  5. ClearSky Charming Kitten Dec 2017 — ClearSky Cyber Security. (2017, December). Charming Kitten. Retrieved December 27, 2017.
  6. ClearSky Kittens Back 2 Oct 2019 — ClearSky Research Team. (2019, October 1). The Kittens Are Back in Town2 - Charming Kitten Campaign KeepsGoing on, Using New Impersonation Methods. Retrieved April 21, 2021.
  7. ClearSky Kittens Back 3 August 2020 — ClearSky Research Team. (2020, August 1). The Kittens Are Back in Town 3 - Charming Kitten Campaign Evolved and Deploying Spear-Phishing link by WhatsApp. Retrieved April 21, 2021.
  8. Eweek Newscaster and Charming Kitten May 2014 — Kerner, S. (2014, May 29). Newscaster Threat Uses Social Media for Intelligence Gathering. Retrieved April 14, 2021.
  9. Unit 42 Magic Hound Feb 2017 — Lee, B. and Falcone, R. (2017, February 15). Magic Hound Campaign Attacks Saudi Targets. Retrieved December 27, 2017.
  10. FireEye APT35 2018 — Mandiant. (2018). Mandiant M-Trends 2018. Retrieved November 17, 2024.
  11. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  12. Proofpoint TA453 July2021 — Miller, J. et al. (2021, July 13). Operation SpoofedScholars: A Conversation with TA453. Retrieved August 18, 2021.
  13. Proofpoint TA453 March 2021 — Miller, J. et al. (2021, March 30). BadBlood: TA453 Targets US and Israeli Medical Research Personnel in Credential Phishing Campaigns. Retrieved May 4, 2021.
  14. Secureworks COBALT ILLUSION Threat Profile — Secureworks. (n.d.). COBALT ILLUSION Threat Profile. Retrieved April 14, 2021.
  15. US District Court of DC Phosphorus Complaint 2019 — US District Court of DC. (2019, March 14). MICROSOFT CORPORATION v. JOHN DOES 1-2, CONTROLLING A COMPUTER NETWORK AND THEREBY INJURING PLAINTIFF AND ITS CUSTOMERS. Retrieved March 8, 2021.
  16. IBM ITG18 2020 — Wikoff, A. Emerson, R. (2020, July 16). New Research Exposes Iranian Threat Group Operations. Retrieved March 8, 2021.

Intel Summary

78

Techniques

26

Tools

3

Campaigns

0

IOCs

0

Observed Data

14

Tactics

Tags

APT
Critical Infrastructure
Government Targeting

Details

MITRE ID
G0059
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--f9d6633a-55e6-4adc-9263-6ae080421a13
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.