Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets – Dark Reading
Conflicts in the Middle East, Ukraine, and other areas of simmering geopolitical tensions have made policy experts the latest target of cyber operations conducted by state-sponsored groups.
An Iran-linked group known as Charming Kitten, CharmingCypress, and APT42 recently targeted Middle East policy experts in the region as well as in the US and Europe, using a phony webinar platform to compromise its targeted victims, incident response services firm Volexity stated in an advisory published this month.
Charming Kitten is well known for its extensive social engineering tactics, including low-and-slow social engineering attacks against think tanks and journalists to gather political intelligence, the firm stated.
The group often dupes is targets into installing Trojan-rigged VPN applications to gain access to the fake webinar platform and other sites, resulting in the installation of malware. Overall, the group has embraced the long confidence game, says Steven Adair, co-founder and president of Volexity.
"I don't know if that is necessarily sophisticated and advanced, but it is a lot of effort," he says. "It's more advanced and more sophisticated than your average attack by a significant margin. It's a level of effort and dedication ... that is definitely different and uncommon ... to go to that much effort for such a specific set of attacks."
Policy experts are a frequently targeted by nation-state groups. The Russia-linked ColdRiver group, for example, has targeted nongovernmental organizations, military officers, and other experts using social engineering to gain the confidence of the victim and then following up with a malicious link or malware. In Jordan, targeted exploitation reportedly by government agencies used the Pegasus spyware program developed by the NSO Group and targeted journalists, digital-rights lawyers, and other policy experts.
Other companies have also described Charming Kitten/CharmingCypress' tactics. In a January advisory, Microsoft warned that the group, which it calls Mint Sandstorm, had targeted journalists, researchers, professors, and other experts covering security and policy topics of interest to the Iranian government.
"Operators associated with this subgroup of Mint Sandstorm are patient and highly skilled social engineers whose tradecraft lacks many of the hallmarks that allow users to quickly identify phishing emails," Microsoft stated. "In some instances of this campaign, this subgroup also used legitimate but compromised accounts to send phishing lures."
The group has been active since at least 2013, has strong links to the Islamic Revolutionary Guard Corps (IRGC), and has not been directly involved in the cyber-operational aspect of the conflict between Israel and Hamas, according to cybersecurity firm CrowdStrike.
"Unlike in the Russia-Ukraine war, where known cyber operations have directly contributed to the conflict, those involved in the Israel-Hamas conflict have not directly contributed to Hamas military operations against Israel," the company stated in its "2024 Global Threat Report" released on Feb. 21.
These attacks usually start with spear-phishing and end with a combination of malware delivered to the target's system, according to an advisory from Volexity, which calls the group CharmingCypress. In September and October 2023, CharmingCypress used a number of typo-squatted domains addresses similar to legitimate domains to pose as officials from the International Institute of Iranian Studies (IIIS) to invite policy experts to a webinar. The initial email demonstrated the low-and-slow approach of CharmingCypress, eschewing any malicious link or attachment and inviting the targeted professional to reach out through other channels of communications, such as WhatsApp and Signal.
Using in-depth spearphishing, CharmingCypress aims to convince policy experts to install malware. Source: Volexity
The attacks target Middle East policy experts worldwide, with Volexity encountering a majority of attacks against European and US professionals, Adair says.
"They are quite aggressive," he says. "They'll even set up entire email chains or a phishing scenario where they're looking for comment and there's other people maybe three, four, or five people on that email thread with the exception of the target they're definitely trying to build rapport."
The long con eventually delivers a payload. Volexity identified five different malware families associated with the threat. The PowerLess backdoor is installed by the Windows version of the malware-laden virtual private network (VPN) application, which uses PowerShell to allow files to be transferred and executed, as well as targeting specific data on the system, logging keystrokes, and capturing screenshots. A macOS version of the malware is dubbed NokNok, while a separate malware chain using a RAR archive and LNK exploit leads to a backdoor named Basicstar.
The group's approach to social engineering definitely embodies the "persistence" piece of the advanced persistent threat (APT). Volexity sees a "constant barrage" of attacks, so policy experts have to become even more suspicious of cold contacts, Adair says.
Doing so will be difficult, as many policy experts are academics in constant contact with students or members of the public and are not used to being strict with their contacts, he says. Yet they should definitely think before opening documents or entering credentials into a site reached through an unknown link.
"At the end of the day, they have to get the person to click something or open something, which if I want you to review a paper or something like that, means ... being very wary of links and files," Adair says. "If I have to enter my credentials at any point in time, or authorize something that should be a major red flag. Similarly, if I'm being asked to download something, that should be a pretty big red flag."
In addition, policy experts need to understand that CharmingCypress will continue to target them even if its attempts fail, Volexity stated.
"This threat actor is highly committed to conducting surveillance on their targets in order to determine how best to manipulate them and deploy malware," the company stated in its advisory. "Additionally, few other threat actors have consistently churned out as many campaigns as CharmingCypress, dedicating human operators to support their ongoing efforts."
Originally posted here:
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets - Dark Reading
- The Iran Wars Threat to Turkey - Foreign Affairs - April 27th, 2026 [April 27th, 2026]
- KC area drivers sound off on high gas prices, the Iran war. We all know who to blame - Kansas City Star - April 27th, 2026 [April 27th, 2026]
- Report: Iran has caused billions in damage to US military bases in Gulf region - The Hill - April 27th, 2026 [April 27th, 2026]
- Live updates: German leader says US humiliated by Iran - NewsNation - April 27th, 2026 [April 27th, 2026]
- Live Updates: Latest from Israel, Iran, and the Middle East - The Jerusalem Post - April 27th, 2026 [April 27th, 2026]
- Middle East war live: Iran says its army should be authority of Hormuz, wants payments in rial - France 24 - April 27th, 2026 [April 27th, 2026]
- Iran's 'Quadruple' Warning To Gulf Nations After Trump's Threats - NDTV - April 27th, 2026 [April 27th, 2026]
- The Iran war could drive up costs for petroleum-derived products like clothes and crayons - AP News - April 27th, 2026 [April 27th, 2026]
- Iran offers to reopen Strait of Hormuz if U.S. lifts its blockade and the war ends, officials say - PBS - April 27th, 2026 [April 27th, 2026]
- Live updates: Iran offers to reopen Strait of Hormuz if US lifts its blockade and the war ends, officials say - AP News - April 27th, 2026 [April 27th, 2026]
- How the Iran war is bringing back 'citizenship as a weapon' - DW.com - April 27th, 2026 [April 27th, 2026]
- How the West Can Escape Iran's Hormuz Trap - Foreign Policy - April 27th, 2026 [April 27th, 2026]
- Iran-US war latest: Entire nation is being humiliated by Tehran, says Merz - The Independent - April 27th, 2026 [April 27th, 2026]
- Trumps indifference to Iran and Russias military collaboration is staggering - The Independent - April 27th, 2026 [April 27th, 2026]
- 2 months into the Iran war, who holds the upper hand? - South China Morning Post - April 27th, 2026 [April 27th, 2026]
- Despite a New Proposal From Iran, Ceasefire Negotiations With US Are in Flux - Military.com - April 27th, 2026 [April 27th, 2026]
- Iran proposes to reopen Strait of Hormuz without nuclear agreement. Follow live updates. - The Boston Globe - April 27th, 2026 [April 27th, 2026]
- Trump says Iran can phone if it wants to talk; Iranian minister heads to Russia - Yahoo - April 27th, 2026 [April 27th, 2026]
- Iran gave US a proposal for reopening the Strait Of Hormuz and ending the war, Axios reports - Reuters - April 27th, 2026 [April 27th, 2026]
- Iran turmoil erupts: Ultra-hardliner who mocked Trump poised to take over nuclear talks - Yahoo - April 27th, 2026 [April 27th, 2026]
- 5 things to know for April 27: Press dinner shooting, Severe weather, King Charles, Iran war, fossil fuel profits - CNN - April 27th, 2026 [April 27th, 2026]
- Iran offers to reopen Strait of Hormuz if US lifts its blockade and the war ends, officials say - WRAL - April 27th, 2026 [April 27th, 2026]
- The Iran war has the world buying more clean energy. China stands to benefit the most - CNN - April 27th, 2026 [April 27th, 2026]
- Trump to hold talks on Iran with security team, US media say - Euronews.com - April 27th, 2026 [April 27th, 2026]
- Mediators still seek to bridge US, Iran gaps despite failure of face-to-face talks - Yahoo - April 27th, 2026 [April 27th, 2026]
- The war on Iran is eroding nuclear non-proliferation - Al Jazeera - April 27th, 2026 [April 27th, 2026]
- Trump says Iran can phone if it wants to talk; Iranian minister heads to Russia - KSL.com - April 27th, 2026 [April 27th, 2026]
- Iran is suffering in a standoff with the US but may be betting Trump will blink first - CNN - April 27th, 2026 [April 27th, 2026]
- Iran has played their last cards in the war, says Heritage Foundation's Steve Yates - CNBC - April 27th, 2026 [April 27th, 2026]
- The Iran War and How It Might End - Geopolitical Futures - April 27th, 2026 [April 27th, 2026]
- Trump voters say the pope should 'stay in his lane' and butt out of the Iran war - NBC News - April 19th, 2026 [April 19th, 2026]
- Middle East crisis live: Iran says fundamental issues still to be resolved with US amid strait of Hormuz impasse - The Guardian - April 19th, 2026 [April 19th, 2026]
- Strait of Hormuz blocked as gaps remain on Iran peace talks - Reuters - April 19th, 2026 [April 19th, 2026]
- Iran war: What is happening on day 51 of the US-Iran conflict? - Al Jazeera - April 19th, 2026 [April 19th, 2026]
- Trump: Iran got a little cute by blocking Hormuz again, but talks going really well - The Times of Israel - April 19th, 2026 [April 19th, 2026]
- Iran war: What is happening on day 50 of the US-Iran conflict? - Al Jazeera - April 19th, 2026 [April 19th, 2026]
- The U.S. is ready to seize Iran-linked ships with boarding parties, report says, while Marines practice maritime raids - Fortune - April 19th, 2026 [April 19th, 2026]
- Report: Iran still able to access around 70% of its pre-war missile stocks, 60% of launchers - The Times of Israel - April 19th, 2026 [April 19th, 2026]
- Iran fully closes Strait of Hormuz over US blockade and fires on ships - AP News - April 19th, 2026 [April 19th, 2026]
- Why China is taking a behind-the-scenes role in the Iran war - The Washington Post - April 19th, 2026 [April 19th, 2026]
- In Qatar, Trapped Between the U.S. and Iran, War Forced a Reckoning - The New York Times - April 19th, 2026 [April 19th, 2026]
- Traders placed over $1bn in perfectly timed bets on the Iran war. What is going on? - The Guardian - April 19th, 2026 [April 19th, 2026]
- Heres what the stock market might have gotten wrong about the Iran war - The Washington Post - April 19th, 2026 [April 19th, 2026]
- After war of words on Iran, Pope Leo says he's not interested in a debate with Trump - NBC News - April 19th, 2026 [April 19th, 2026]
- Iran war: What is happening on day 49 of the US-Iran conflict? - Al Jazeera - April 19th, 2026 [April 19th, 2026]
- Iran parliament speaker touts progress in US talks, but Strait of Hormuz still shut - The Times of Israel - April 19th, 2026 [April 19th, 2026]
- Trump, Iran cite progress in talks as uncertainty hangs over Strait - KSL News - April 19th, 2026 [April 19th, 2026]
- What has Trump said before possible US-Iran talks and what could it mean? - Al Jazeera - April 19th, 2026 [April 19th, 2026]
- Trump keeps claiming victory in Iran. Our new poll shows voters arent buying it. - Politico - April 19th, 2026 [April 19th, 2026]
- The Iran war has revealed Trump's pressure point: the economy - Reuters - April 19th, 2026 [April 19th, 2026]
- The Iran war has exposed the limits of neutrality - Al Jazeera - April 19th, 2026 [April 19th, 2026]
- Smerconish: To end the Iran conflict, Congress must authorize it - CNN - April 19th, 2026 [April 19th, 2026]
- Faisal Islam: What people in power think the impact of the Iran war will be - BBC - April 19th, 2026 [April 19th, 2026]
- What's it like to negotiate with Iran? We asked people who have done it - NPR - April 19th, 2026 [April 19th, 2026]
- Opinion: All the good US did after WWII squandered with Iran war - The Asheville Citizen Times - April 19th, 2026 [April 19th, 2026]
- Iran doubles down on closing the Strait of Hormuz as the ceasefire nears expiration - AP News - April 19th, 2026 [April 19th, 2026]
- Diplomatic cables show Iran war is damaging US on multiple fronts across the world - Politico - April 19th, 2026 [April 19th, 2026]
- The most politically charged World Cup ever puts the U.S. and Iran on a collision course while America co-hosts with neighbors it has tariffed -... - April 19th, 2026 [April 19th, 2026]
- Trump is savaging allies who criticize the Iran war. But hes treating Joe Rogan very differently - CNN - April 19th, 2026 [April 19th, 2026]
- GOP senators urge Trump to find Iran exit plan as energy prices rise: The clock is ticking - Politico - April 19th, 2026 [April 19th, 2026]
- White House Declines to Offer Congress an Estimate of Iran War Cost - The New York Times - April 17th, 2026 [April 17th, 2026]
- US House rejects war powers resolution aimed at limiting Iran War - BBC - April 17th, 2026 [April 17th, 2026]
- Why a U.S. blockade on Iran seems to be working - PBS - April 17th, 2026 [April 17th, 2026]
- Israel starts a tense ceasefire in Lebanon, as Trump sounds optimistic on Iran talks - NPR - April 17th, 2026 [April 17th, 2026]
- House narrowly rejects resolution directing Trump to end hostilities in Iran - The Washington Post - April 17th, 2026 [April 17th, 2026]
- Pakistan Looks to Play Peacemaker Between U.S. and Iran, Again - The New York Times - April 17th, 2026 [April 17th, 2026]
- World Insights: Key conservative influencers turn against Trump over Iran - Xinhua - April 17th, 2026 [April 17th, 2026]
- Trump says Iran has agreed to hand over enriched uranium - Le Monde.fr - April 17th, 2026 [April 17th, 2026]
- It's time to start thinking about the post-Iran war market environment: Lombard Odier - CNBC - April 17th, 2026 [April 17th, 2026]
- House effort to end Trump's war with Iran fails by one vote - NBC News - April 17th, 2026 [April 17th, 2026]
- Pete Hegseth says Iran is digging out missiles and launchers - NBC News - April 17th, 2026 [April 17th, 2026]
- Opinion | Iran is dangling its favorite kind of deal. Will Trump bite? - The Washington Post - April 17th, 2026 [April 17th, 2026]
- Behind the bluster, Donald Trump desperately needs a peace deal with Iran. Here's a solution | Rajan Menon - The Guardian - April 17th, 2026 [April 17th, 2026]
- It's Not Working: Diplomats Fear Trump's Iran Envoys Are Making Things Worse - Time Magazine - April 17th, 2026 [April 17th, 2026]
- Trump says the economy is thriving 'despite our little diversion' in Iran - NBC News - April 17th, 2026 [April 17th, 2026]
- Trump says it is important for Pope to understand Iran is a global threat - Reuters - April 17th, 2026 [April 17th, 2026]
- What role is China playing in the Iran war and how is it affected? - Al Jazeera - April 17th, 2026 [April 17th, 2026]
- Trump Bets Economic Pain Will Finally Force Iran to Reopen Strait - WSJ - April 17th, 2026 [April 17th, 2026]
- Hegseth says US is locked and loaded to finish job of destroying Iran energy grid - The Guardian - April 17th, 2026 [April 17th, 2026]
- Trump touts tax tips policy in Vegas, says Iran war is going 'swimmingly' - USA Today - April 17th, 2026 [April 17th, 2026]