Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets – Dark Reading
Conflicts in the Middle East, Ukraine, and other areas of simmering geopolitical tensions have made policy experts the latest target of cyber operations conducted by state-sponsored groups.
An Iran-linked group known as Charming Kitten, CharmingCypress, and APT42 recently targeted Middle East policy experts in the region as well as in the US and Europe, using a phony webinar platform to compromise its targeted victims, incident response services firm Volexity stated in an advisory published this month.
Charming Kitten is well known for its extensive social engineering tactics, including low-and-slow social engineering attacks against think tanks and journalists to gather political intelligence, the firm stated.
The group often dupes is targets into installing Trojan-rigged VPN applications to gain access to the fake webinar platform and other sites, resulting in the installation of malware. Overall, the group has embraced the long confidence game, says Steven Adair, co-founder and president of Volexity.
"I don't know if that is necessarily sophisticated and advanced, but it is a lot of effort," he says. "It's more advanced and more sophisticated than your average attack by a significant margin. It's a level of effort and dedication ... that is definitely different and uncommon ... to go to that much effort for such a specific set of attacks."
Policy experts are a frequently targeted by nation-state groups. The Russia-linked ColdRiver group, for example, has targeted nongovernmental organizations, military officers, and other experts using social engineering to gain the confidence of the victim and then following up with a malicious link or malware. In Jordan, targeted exploitation reportedly by government agencies used the Pegasus spyware program developed by the NSO Group and targeted journalists, digital-rights lawyers, and other policy experts.
Other companies have also described Charming Kitten/CharmingCypress' tactics. In a January advisory, Microsoft warned that the group, which it calls Mint Sandstorm, had targeted journalists, researchers, professors, and other experts covering security and policy topics of interest to the Iranian government.
"Operators associated with this subgroup of Mint Sandstorm are patient and highly skilled social engineers whose tradecraft lacks many of the hallmarks that allow users to quickly identify phishing emails," Microsoft stated. "In some instances of this campaign, this subgroup also used legitimate but compromised accounts to send phishing lures."
The group has been active since at least 2013, has strong links to the Islamic Revolutionary Guard Corps (IRGC), and has not been directly involved in the cyber-operational aspect of the conflict between Israel and Hamas, according to cybersecurity firm CrowdStrike.
"Unlike in the Russia-Ukraine war, where known cyber operations have directly contributed to the conflict, those involved in the Israel-Hamas conflict have not directly contributed to Hamas military operations against Israel," the company stated in its "2024 Global Threat Report" released on Feb. 21.
These attacks usually start with spear-phishing and end with a combination of malware delivered to the target's system, according to an advisory from Volexity, which calls the group CharmingCypress. In September and October 2023, CharmingCypress used a number of typo-squatted domains addresses similar to legitimate domains to pose as officials from the International Institute of Iranian Studies (IIIS) to invite policy experts to a webinar. The initial email demonstrated the low-and-slow approach of CharmingCypress, eschewing any malicious link or attachment and inviting the targeted professional to reach out through other channels of communications, such as WhatsApp and Signal.
Using in-depth spearphishing, CharmingCypress aims to convince policy experts to install malware. Source: Volexity
The attacks target Middle East policy experts worldwide, with Volexity encountering a majority of attacks against European and US professionals, Adair says.
"They are quite aggressive," he says. "They'll even set up entire email chains or a phishing scenario where they're looking for comment and there's other people maybe three, four, or five people on that email thread with the exception of the target they're definitely trying to build rapport."
The long con eventually delivers a payload. Volexity identified five different malware families associated with the threat. The PowerLess backdoor is installed by the Windows version of the malware-laden virtual private network (VPN) application, which uses PowerShell to allow files to be transferred and executed, as well as targeting specific data on the system, logging keystrokes, and capturing screenshots. A macOS version of the malware is dubbed NokNok, while a separate malware chain using a RAR archive and LNK exploit leads to a backdoor named Basicstar.
The group's approach to social engineering definitely embodies the "persistence" piece of the advanced persistent threat (APT). Volexity sees a "constant barrage" of attacks, so policy experts have to become even more suspicious of cold contacts, Adair says.
Doing so will be difficult, as many policy experts are academics in constant contact with students or members of the public and are not used to being strict with their contacts, he says. Yet they should definitely think before opening documents or entering credentials into a site reached through an unknown link.
"At the end of the day, they have to get the person to click something or open something, which if I want you to review a paper or something like that, means ... being very wary of links and files," Adair says. "If I have to enter my credentials at any point in time, or authorize something that should be a major red flag. Similarly, if I'm being asked to download something, that should be a pretty big red flag."
In addition, policy experts need to understand that CharmingCypress will continue to target them even if its attempts fail, Volexity stated.
"This threat actor is highly committed to conducting surveillance on their targets in order to determine how best to manipulate them and deploy malware," the company stated in its advisory. "Additionally, few other threat actors have consistently churned out as many campaigns as CharmingCypress, dedicating human operators to support their ongoing efforts."
Originally posted here:
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets - Dark Reading
- Iran's Pezeshkian says Tehran seeks peace, but will not bow to coercion - Reuters - November 7th, 2025 [November 7th, 2025]
- IAEA chief says Iran still capable of building nuclear weapons | Iran International - - November 7th, 2025 [November 7th, 2025]
- Cultural Genocide and the Kurdish Struggle in Iran - Genocide Watch - November 7th, 2025 [November 7th, 2025]
- Iran Fears Gen-Z: Why the Regime Is Ratcheting Up Propaganda - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- Iran plotted to kill Israeli ambassador to Mexico, US and Israeli officials say - The Times of Israel - November 7th, 2025 [November 7th, 2025]
- Iran planned to kill Israeli envoy to Mexico this year - JNS.org - November 7th, 2025 [November 7th, 2025]
- Iran: Protest in Ahvaz Following Shocking Self-Immolation of 20-Year-Old Ahmad Baldi - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- Iran says open to negotiation but will not give up nuclear - The Jerusalem Post - November 7th, 2025 [November 7th, 2025]
- Marginalization of the Baloch in Iran - Genocide Watch - November 7th, 2025 [November 7th, 2025]
- Pezeshkian: Iran seeks peace, but wont give up its nuclear and missile programs - The Times of Israel - November 7th, 2025 [November 7th, 2025]
- Jewish Iranian-American sentenced to prison in Iran for visiting Israel 13 years ago - Jewish Telegraphic Agency - November 7th, 2025 [November 7th, 2025]
- Iran News in Brief November 7, 2025 - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- After its drone success, Iran's next breakout hit could come from the sea - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Surviving 903 Days of Torture and Sexual Assault by Iran-Backed Shia Militias - IranWire - November 7th, 2025 [November 7th, 2025]
- Iran Arrests Baha'is in Wave of Raids Across Multiple Provinces - IranWire - November 7th, 2025 [November 7th, 2025]
- Trump says Iran has asked about lifting US sanctions - - November 7th, 2025 [November 7th, 2025]
- Iran unveils monument to ancient victory in show of post-war defiance - RFI - November 7th, 2025 [November 7th, 2025]
- Iran condemns Israels breach of truce and strikes on Lebanon - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Iran: US Citizen Hekmati, 70, Sentenced to 4 Years Over Trip to Israel in 2012 - EA WorldView - November 7th, 2025 [November 7th, 2025]
- Iran submits three films to 1st Open Eurasian Film Award Diamond Butterfly - Tehran Times - November 7th, 2025 [November 7th, 2025]
- IDF reveals Hamas ties to Iran, UNRWA, Al Jazeera, stolen aid in collection of documents - The Jerusalem Post - November 7th, 2025 [November 7th, 2025]
- Iran unveils monument to ancient victory in show of post-war defiance - Homenewshere.com - November 7th, 2025 [November 7th, 2025]
- Iranian-American poets son arrested over Detroit terror plot | Iran International - - November 7th, 2025 [November 7th, 2025]
- Average age of first-time mothers in Iran continues to rise - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Iran planned to assassinate Israel's ambassador to Mexico, but the attempt was thwarted - US official - - November 7th, 2025 [November 7th, 2025]
- Between Mediation and Advocacy: Omans Shifting Role in Gulf-Iran Relations - orfonline.org - November 7th, 2025 [November 7th, 2025]
- Not if they say we will bomb you: Pezeshkian says Iran seeks peace, but wont abandon nuke programme - WION - November 7th, 2025 [November 7th, 2025]
- Soroka to receive over $300 million to rebuild after Iran missile strike in June - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Iran: Human rights investigators alarmed by surge in repression and spike in executions following Israeli airstrikes - UN News - November 3rd, 2025 [November 3rd, 2025]
- Iran says wont dismantle missiles, ready for war with Israel - JNS.org - November 3rd, 2025 [November 3rd, 2025]
- Irans Ruling Class Turns on Itself as Crises Deepen - National Council of Resistance of Iran - NCRI - November 3rd, 2025 [November 3rd, 2025]
- Is this the end of Iran's Islamic Revolution? - The Jerusalem Post - November 3rd, 2025 [November 3rd, 2025]
- Dead Sea hotel worker charged with spying for Iran; was asked for intel on Ben Gvir - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Iran's Bitcoin Mining Industry: Inside the World's Fifth-Largest Operation Amid Sanctions and Energy Crisis - Brave New Coin - November 3rd, 2025 [November 3rd, 2025]
- Russian FM says no limits for military cooperation with Iran - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Araghchi says Israel duped US on Iran threat, urges Trump to reverse course - - November 3rd, 2025 [November 3rd, 2025]
- Former Israeli Ambassador Warns That Iran, Russia, and China Are Expanding Terror Sleeper Cells Across the US - VINnews - November 3rd, 2025 [November 3rd, 2025]
- In the past 48 hours, the heinous lie that the unlawful Israeli and U.S. bombing of Iran was motivated by an imminent nuclear threat has been... - November 3rd, 2025 [November 3rd, 2025]
- Iran To Build 8 New Nuclear Plants With Russias Help - Eurasia Review - November 3rd, 2025 [November 3rd, 2025]
- At the heart of regional architecture, Iran is inevitable - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Iran promises to rebuild bombed nuclear sites "with greater strength" after US strikes - Euromaidan Press - November 3rd, 2025 [November 3rd, 2025]
- We will not be set back: Pezeshkian vows Iran will rebuild its nuclear sites stronger than before - WION - November 3rd, 2025 [November 3rd, 2025]
- Iran banking on Iraq vote to retain regional influence - Citizen Tribune - November 3rd, 2025 [November 3rd, 2025]
- Iran vows to rebuild nuclear facilities 'with greater strength' after US strikes - Trkiye Today - November 3rd, 2025 [November 3rd, 2025]
- UK Parliament Conference Calls For Firm Policy On Iran Amid Surge In Executions OpEd - Eurasia Review - November 3rd, 2025 [November 3rd, 2025]
- Regional Museum of Southeastern Iran, a mirror of Iranian culture, civilization - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Charges filed against Tiberias man suspected of spying for Iran - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Repression in Iran worsened after 12-day war with Israel in June, UN probe finds - The Times of Israel - October 31st, 2025 [October 31st, 2025]
- As Renewal of Iran-Israel War Looms, What Lessons Can Be Learned from June? - Middle East Council on Global Affairs - October 31st, 2025 [October 31st, 2025]
- Mediator Egypt urges end to impasse over Iran nuclear inspections - - October 31st, 2025 [October 31st, 2025]
- Faith, knowledge, and steadfastness: Ayatollah Khameneis vision for an independent Iran - Tehran Times - October 31st, 2025 [October 31st, 2025]
- Two men sentenced to 25 years over Iran-backed plot to kill dissident - Reuters - October 31st, 2025 [October 31st, 2025]
- Socioeconomic disparities in urological cancers in iran: a systematic analysis for the Global Burden of Disease study 2019 - BMC Public Health - October 31st, 2025 [October 31st, 2025]
- UN accuses Iran of widespread arrests, abuses after 12-day war with Israel - France 24 - October 31st, 2025 [October 31st, 2025]
- Iran says UN watchdog should not express 'unfounded opinions' on nuclear programme - Reuters - October 31st, 2025 [October 31st, 2025]
- Iran participating in 28th Algiers International Book Fair - Tehran Times - October 31st, 2025 [October 31st, 2025]
- Hassan Rouhani wants to be the next Supreme Leader. Iran's hardliners won't have it - thenationalnews.com - October 31st, 2025 [October 31st, 2025]
- Egypt mediates talks between Iran and the IAEA on nuclear program cooperation - Latest news from Azerbaijan - October 31st, 2025 [October 31st, 2025]
- Artist Sheida Soleimani renders story of her parents' escape from Iran - The Business Journals - October 31st, 2025 [October 31st, 2025]
- Niger Joins Haiti, Russia, Iran, and Iraq in the US List of Do Not Travel Urgent Warnings The Hidden Dangers That Could Put Your Life at Risk! -... - October 31st, 2025 [October 31st, 2025]
- IDF, Mossad on alert for Oct. 7-style threat from Iran-backed militias in Iraq - Yahoo - October 31st, 2025 [October 31st, 2025]
- Egypt, Iran, IAEA discuss steps toward peaceful resolution of Tehrans nuclear issue - Trkiye Today - October 31st, 2025 [October 31st, 2025]
- Iran, Russia and the New Zealand insurer that kept their sanctioned oil flowing - Reuters - October 28th, 2025 [October 28th, 2025]
- Iran declares bankruptcy of major bank as country grapples with restored sanctions - The Times of Israel - October 28th, 2025 [October 28th, 2025]
- CSIS Satellite Imagery Analysis Reveals Possible Signs of Renewed Nuclear Activity in Iran - CSIS | Center for Strategic and International Studies - October 28th, 2025 [October 28th, 2025]
- British woman's 'spirits were low' on phone call from Iran prison - BBC - October 28th, 2025 [October 28th, 2025]
- Why is the UN directing tourists into Iran? - The Telegraph - October 28th, 2025 [October 28th, 2025]
- Iran News in Brief October 28, 2025 - National Council of Resistance of Iran - NCRI - October 28th, 2025 [October 28th, 2025]
- Russia says no rift with Iran as row over Moscow role heats up in Tehran | Iran International - - October 28th, 2025 [October 28th, 2025]
- Irans Education System Paralyzed as Regime Diverts Resources to Nuclear and Military Programs - National Council of Resistance of Iran - NCRI - October 28th, 2025 [October 28th, 2025]
- Irans Rappers: Voices of Dissent, Targets of the State - Center for Human Rights in Iran - October 28th, 2025 [October 28th, 2025]
- Satellite images reveal possible renewed nuclear activity in Iran - think tank - - October 28th, 2025 [October 28th, 2025]
- From FATF to Bank Meltdown, Irans Power Factions Clash on Every Front - National Council of Resistance of Iran - NCRI - October 28th, 2025 [October 28th, 2025]
- Political Prisoner on Fifth Day of Hunger Strike in Iran - IranWire - October 28th, 2025 [October 28th, 2025]
- Iran-UAE dispute over three islands in Gulf heats up - The New Arab - October 28th, 2025 [October 28th, 2025]
- Family of British couple detained in Iran issue update after recent court hearing had not gone well - The Independent - October 28th, 2025 [October 28th, 2025]
- Iran Establishes Itself As A Missile Superpower Through Advanced Precision And Hypersonic Technology - Iran - Iran Front Page - IFP News - October 28th, 2025 [October 28th, 2025]
- Iran stresses key role of Islamic unity in face of foreign threats - taghribnews.com - October 28th, 2025 [October 28th, 2025]
- Iran criticizes UN for failure to act on Israeli-imposed war on Tehran - taghribnews.com - October 28th, 2025 [October 28th, 2025]
- As '80s Iran convulsed, L.A. immigrants honed new sounds. This album lauds them - with warnings for today - Los Angeles Times - October 28th, 2025 [October 28th, 2025]