Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets – Dark Reading
Conflicts in the Middle East, Ukraine, and other areas of simmering geopolitical tensions have made policy experts the latest target of cyber operations conducted by state-sponsored groups.
An Iran-linked group known as Charming Kitten, CharmingCypress, and APT42 recently targeted Middle East policy experts in the region as well as in the US and Europe, using a phony webinar platform to compromise its targeted victims, incident response services firm Volexity stated in an advisory published this month.
Charming Kitten is well known for its extensive social engineering tactics, including low-and-slow social engineering attacks against think tanks and journalists to gather political intelligence, the firm stated.
The group often dupes is targets into installing Trojan-rigged VPN applications to gain access to the fake webinar platform and other sites, resulting in the installation of malware. Overall, the group has embraced the long confidence game, says Steven Adair, co-founder and president of Volexity.
"I don't know if that is necessarily sophisticated and advanced, but it is a lot of effort," he says. "It's more advanced and more sophisticated than your average attack by a significant margin. It's a level of effort and dedication ... that is definitely different and uncommon ... to go to that much effort for such a specific set of attacks."
Policy experts are a frequently targeted by nation-state groups. The Russia-linked ColdRiver group, for example, has targeted nongovernmental organizations, military officers, and other experts using social engineering to gain the confidence of the victim and then following up with a malicious link or malware. In Jordan, targeted exploitation reportedly by government agencies used the Pegasus spyware program developed by the NSO Group and targeted journalists, digital-rights lawyers, and other policy experts.
Other companies have also described Charming Kitten/CharmingCypress' tactics. In a January advisory, Microsoft warned that the group, which it calls Mint Sandstorm, had targeted journalists, researchers, professors, and other experts covering security and policy topics of interest to the Iranian government.
"Operators associated with this subgroup of Mint Sandstorm are patient and highly skilled social engineers whose tradecraft lacks many of the hallmarks that allow users to quickly identify phishing emails," Microsoft stated. "In some instances of this campaign, this subgroup also used legitimate but compromised accounts to send phishing lures."
The group has been active since at least 2013, has strong links to the Islamic Revolutionary Guard Corps (IRGC), and has not been directly involved in the cyber-operational aspect of the conflict between Israel and Hamas, according to cybersecurity firm CrowdStrike.
"Unlike in the Russia-Ukraine war, where known cyber operations have directly contributed to the conflict, those involved in the Israel-Hamas conflict have not directly contributed to Hamas military operations against Israel," the company stated in its "2024 Global Threat Report" released on Feb. 21.
These attacks usually start with spear-phishing and end with a combination of malware delivered to the target's system, according to an advisory from Volexity, which calls the group CharmingCypress. In September and October 2023, CharmingCypress used a number of typo-squatted domains addresses similar to legitimate domains to pose as officials from the International Institute of Iranian Studies (IIIS) to invite policy experts to a webinar. The initial email demonstrated the low-and-slow approach of CharmingCypress, eschewing any malicious link or attachment and inviting the targeted professional to reach out through other channels of communications, such as WhatsApp and Signal.
Using in-depth spearphishing, CharmingCypress aims to convince policy experts to install malware. Source: Volexity
The attacks target Middle East policy experts worldwide, with Volexity encountering a majority of attacks against European and US professionals, Adair says.
"They are quite aggressive," he says. "They'll even set up entire email chains or a phishing scenario where they're looking for comment and there's other people maybe three, four, or five people on that email thread with the exception of the target they're definitely trying to build rapport."
The long con eventually delivers a payload. Volexity identified five different malware families associated with the threat. The PowerLess backdoor is installed by the Windows version of the malware-laden virtual private network (VPN) application, which uses PowerShell to allow files to be transferred and executed, as well as targeting specific data on the system, logging keystrokes, and capturing screenshots. A macOS version of the malware is dubbed NokNok, while a separate malware chain using a RAR archive and LNK exploit leads to a backdoor named Basicstar.
The group's approach to social engineering definitely embodies the "persistence" piece of the advanced persistent threat (APT). Volexity sees a "constant barrage" of attacks, so policy experts have to become even more suspicious of cold contacts, Adair says.
Doing so will be difficult, as many policy experts are academics in constant contact with students or members of the public and are not used to being strict with their contacts, he says. Yet they should definitely think before opening documents or entering credentials into a site reached through an unknown link.
"At the end of the day, they have to get the person to click something or open something, which if I want you to review a paper or something like that, means ... being very wary of links and files," Adair says. "If I have to enter my credentials at any point in time, or authorize something that should be a major red flag. Similarly, if I'm being asked to download something, that should be a pretty big red flag."
In addition, policy experts need to understand that CharmingCypress will continue to target them even if its attempts fail, Volexity stated.
"This threat actor is highly committed to conducting surveillance on their targets in order to determine how best to manipulate them and deploy malware," the company stated in its advisory. "Additionally, few other threat actors have consistently churned out as many campaigns as CharmingCypress, dedicating human operators to support their ongoing efforts."
Originally posted here:
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets - Dark Reading
- Trump says all meetings with Iran are off until crackdown on protesters ends - CNN - January 14th, 2026 [January 14th, 2026]
- At least 2,571 killed in Iran's protests, Trump says 'help is on the way' - Reuters - January 14th, 2026 [January 14th, 2026]
- Heres What to Know About the Protests in Iran - The New York Times - January 14th, 2026 [January 14th, 2026]
- More than 2,000 people reported killed at Iran protests as Trump says 'help is on its way' - BBC - January 14th, 2026 [January 14th, 2026]
- Column | Could Iran go the way of Venezuela? - The Washington Post - January 14th, 2026 [January 14th, 2026]
- Iran latest: Man, 26, to be executed today, says rights group - and more than 2,500 protesters killed - Sky News - January 14th, 2026 [January 14th, 2026]
- Opinion | Ive waited for this electrifying moment in Iran for 10 years - The Washington Post - January 14th, 2026 [January 14th, 2026]
- Trump warns US will take very strong action if Iran starts executing arrested protesters - The Guardian - January 14th, 2026 [January 14th, 2026]
- Iran protest updates: Trump to Iranians- keep protesting, help on the way - Al Jazeera - January 14th, 2026 [January 14th, 2026]
- Why Iran cant afford to shut down the internet forever even if the world doesnt act - The Conversation - January 14th, 2026 [January 14th, 2026]
- Iran protests: what we know so far about the spiralling anti-government demonstrations - The Guardian - January 14th, 2026 [January 14th, 2026]
- 7 highlights from Trump's interview with CBS News: Iran, Renee Good, Jerome Powell and his own morality - CBS News - January 14th, 2026 [January 14th, 2026]
- Oil prices rise more than 2% after Trump cancels meetings with Iran, tells protesters help is on the way - CNBC - January 14th, 2026 [January 14th, 2026]
- Why the massive Iran protests havent toppled its clerical establishment - The Times of Israel - January 14th, 2026 [January 14th, 2026]
- Trump urges Iran protesters to "take over" government institutions - Axios - January 14th, 2026 [January 14th, 2026]
- A long, dire history of US interference in Iran | Letters - The Guardian - January 14th, 2026 [January 14th, 2026]
- Israeli and Arab officials have privately suggested U.S. hold off on Iran strikes - NBC News - January 14th, 2026 [January 14th, 2026]
- Access to Elon Musks Starlink internet service is now free in Iran as regime continues brutal crackdown on protests - CNN - January 14th, 2026 [January 14th, 2026]
- Trump pressures Iran with tariffs that could raise prices in the US - AP News - January 14th, 2026 [January 14th, 2026]
- 'Now there's the threat of executions' in Iran - BBC - January 14th, 2026 [January 14th, 2026]
- Decision time for Trump on Iran but what does he ultimately want? - BBC - January 14th, 2026 [January 14th, 2026]
- Jeremy Bowen: Authoritarian regimes die gradually then suddenly, but Iran is not there yet - BBC - January 14th, 2026 [January 14th, 2026]
- Protests in Iran: Is war with the US or Israel really imminent? - Euronews.com - January 14th, 2026 [January 14th, 2026]
- Trump threatens Greenland and Iran at meeting with oil bosses on Venezuela US politics live - The Guardian - January 9th, 2026 [January 9th, 2026]
- Khamenei says Iran wont back down amid mass protests and Trump threat - The Washington Post - January 9th, 2026 [January 9th, 2026]
- Is this time different in Iran? - vox.com - January 9th, 2026 [January 9th, 2026]
- Opinion | How Trump Makes Good on His Threat to Iran - The Wall Street Journal - January 9th, 2026 [January 9th, 2026]
- How Trump Could Help the People of Iran - The Atlantic - January 9th, 2026 [January 9th, 2026]
- Iran protests are the biggest in years to challenge the regime. Here's what to know. - cbsnews.com - January 9th, 2026 [January 9th, 2026]
- Grave Concern That State Massacre of Protesters is Underway in Iran Amid Internet Blackout - Center for Human Rights in Iran - January 9th, 2026 [January 9th, 2026]
- Growing protests in Iran do not necessarily herald a return to monarchy - The Guardian - January 9th, 2026 [January 9th, 2026]
- A timeline of how the protests in Iran unfolded and grew - AP News - January 9th, 2026 [January 9th, 2026]
- Internet and phones cut in Iran as protesters heed exiled prince's call for mass demonstration - AP News - January 9th, 2026 [January 9th, 2026]
- Iran protests latest: At least 62 killed as Ayatollah threatens harsher crackdown - The Independent - January 9th, 2026 [January 9th, 2026]
- At least 51 people killed during protests so far, rights group says | Iran International - - January 9th, 2026 [January 9th, 2026]
- Why Theres No Starlink Access During Nationwide Shutdown in Iran? - IranWire - January 9th, 2026 [January 9th, 2026]
- Why are there huge protests going on in Iran? - BBC - January 9th, 2026 [January 9th, 2026]
- Iran judiciary chief vows there will be 'decisive' punishment for protesters - abcnews.go.com - January 9th, 2026 [January 9th, 2026]
- What to know about the intensifying protests shaking Iran and putting pressure on its theocracy - PBS - January 9th, 2026 [January 9th, 2026]
- Iran protests: brutal crackdown as uprising gathers pace | The Latest - The Guardian - January 9th, 2026 [January 9th, 2026]
- Iran, Israel, & Immigration | Gregg Roman on The Saad Truth - Middle East Forum - January 9th, 2026 [January 9th, 2026]
- Amid protests, Khamenei digs in, says Iran wont back down to 'saboteurs,' Trump will be overthrown - The Times of Israel - January 9th, 2026 [January 9th, 2026]
- Iran: Deaths and injuries rise amid authorities renewed cycle of protest bloodshed - Amnesty International - January 9th, 2026 [January 9th, 2026]
- How US gave Iran, China, Russia reality check in Venezuela - The Jerusalem Post - January 9th, 2026 [January 9th, 2026]
- Protests Spread in Iran, and Crackdowns Escalate - The New York Times - January 8th, 2026 [January 8th, 2026]
- Iran ready to fight back if US or Israel attacks again, says foreign minister - The Times of Israel - January 8th, 2026 [January 8th, 2026]
- Iran threatens pre-emptive attack if it sees 'indication of threat' - Euronews.com - January 8th, 2026 [January 8th, 2026]
- Iran army chief threatens preemptive attack over 'rhetoric' targeting country after Trump's comments - AP News - January 8th, 2026 [January 8th, 2026]
- Iran is on the edge of revolution - New Statesman - January 8th, 2026 [January 8th, 2026]
- Iran army chief threatens preemptive attack on enemies after Trumps comments - The Independent - January 8th, 2026 [January 8th, 2026]
- What is Happening in Iran | Gregg Roman on Washington Watch - Middle East Forum - January 8th, 2026 [January 8th, 2026]
- Violent clashes reported as Iran protests spread to more areas - BBC - January 8th, 2026 [January 8th, 2026]
- Facing unrest, Iran is on edge as Trump threatens Tehran on heels of Venezuela operation - Los Angeles Times - January 8th, 2026 [January 8th, 2026]
- They are killing us: authorities use force against protesters in Kurdish regions of Iran - The Guardian - January 8th, 2026 [January 8th, 2026]
- 'This Big Truck Is Coming': Iran After The Maduro Kidnapping - FOREVER WARS by Spencer Ackerman - January 8th, 2026 [January 8th, 2026]
- Irans Uprising Expands with Strikes and Demonstrations in Tehran and Other Cities as Youths Clash with Suppressive Forces - National Council of... - January 8th, 2026 [January 8th, 2026]
- Iran says open to US talks but ready for war - The Jerusalem Post - January 8th, 2026 [January 8th, 2026]
- It's the economy: grim livelihoods explain Iranian anger | Iran International - - January 8th, 2026 [January 8th, 2026]
- Out from the margins: how Ilam became the heart of Iran protests - - January 8th, 2026 [January 8th, 2026]
- Iran Says Its Investigating Violence at Weekend Protests - The New York Times - January 8th, 2026 [January 8th, 2026]
- Activists say at least 36 killed amid Iran protests after Trump's warning of a possible U.S. intervention - CBS News - January 8th, 2026 [January 8th, 2026]
- Can Iran's plan for a $7 monthly cash handout calm the streets? | Iran International - - January 8th, 2026 [January 8th, 2026]
- Did a minister just reveal Israeli assets were operating in Iran? - www.israelhayom.com - January 8th, 2026 [January 8th, 2026]
- Could Iran launch preemptive strikes on Israel, US? - The Jerusalem Post - January 8th, 2026 [January 8th, 2026]
- Exiled prince, Kurdish parties call for protests and strikes on Thursday | Iran International - - January 8th, 2026 [January 8th, 2026]
- Iran executes another man accused of spying for Israel, as protests roil country - The Times of Israel - January 8th, 2026 [January 8th, 2026]
- Iranian protesters plead with Trump: 'Don't let them kill us' | Iran International - - January 8th, 2026 [January 8th, 2026]
- Iran's Army chief warns against hostile rhetoric, vows response to threats - AnewZ - January 8th, 2026 [January 8th, 2026]
- Iran accused of deploying Iraqi militias to crush protests at home - middle-east-online.com - January 8th, 2026 [January 8th, 2026]
- Iran warns it may act before an attack if it detects a threat - - January 6th, 2026 [January 6th, 2026]
- Iran protests: 29 killed, over 1,200 arrested by regime - The Jerusalem Post - January 6th, 2026 [January 6th, 2026]
- What Will Happen To Iran As Global And Regional Powers Eye Options? - Forbes - January 6th, 2026 [January 6th, 2026]
- Iran Protests, January 4, 2026 - Institute for the Study of War - January 6th, 2026 [January 6th, 2026]
- Israel hospitals exposed to Iran ballistic missile threat - The Jerusalem Post - January 6th, 2026 [January 6th, 2026]
- Iran has been shaken by a series of protests over the past 50 years. Heres a look at them - AP News - January 6th, 2026 [January 6th, 2026]
- Trumps abduction of Maduro escalates concerns over potential war with Iran - Al Jazeera - January 6th, 2026 [January 6th, 2026]
- What to know about the protests now shaking Iran as tensions remain high over its nuclear program - AP News - January 6th, 2026 [January 6th, 2026]
- Security forces clash with protesters in Iran's main market as at least 35 killed in demonstrations - Los Angeles Times - January 6th, 2026 [January 6th, 2026]
- Rights groups say at least 16 dead in Iran during week of protests - Reuters - January 6th, 2026 [January 6th, 2026]
- Iran protests spread to 222 locations as death toll hits 20 on eighth day | Iran International - - January 6th, 2026 [January 6th, 2026]