Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets – Dark Reading
Conflicts in the Middle East, Ukraine, and other areas of simmering geopolitical tensions have made policy experts the latest target of cyber operations conducted by state-sponsored groups.
An Iran-linked group known as Charming Kitten, CharmingCypress, and APT42 recently targeted Middle East policy experts in the region as well as in the US and Europe, using a phony webinar platform to compromise its targeted victims, incident response services firm Volexity stated in an advisory published this month.
Charming Kitten is well known for its extensive social engineering tactics, including low-and-slow social engineering attacks against think tanks and journalists to gather political intelligence, the firm stated.
The group often dupes is targets into installing Trojan-rigged VPN applications to gain access to the fake webinar platform and other sites, resulting in the installation of malware. Overall, the group has embraced the long confidence game, says Steven Adair, co-founder and president of Volexity.
"I don't know if that is necessarily sophisticated and advanced, but it is a lot of effort," he says. "It's more advanced and more sophisticated than your average attack by a significant margin. It's a level of effort and dedication ... that is definitely different and uncommon ... to go to that much effort for such a specific set of attacks."
Policy experts are a frequently targeted by nation-state groups. The Russia-linked ColdRiver group, for example, has targeted nongovernmental organizations, military officers, and other experts using social engineering to gain the confidence of the victim and then following up with a malicious link or malware. In Jordan, targeted exploitation reportedly by government agencies used the Pegasus spyware program developed by the NSO Group and targeted journalists, digital-rights lawyers, and other policy experts.
Other companies have also described Charming Kitten/CharmingCypress' tactics. In a January advisory, Microsoft warned that the group, which it calls Mint Sandstorm, had targeted journalists, researchers, professors, and other experts covering security and policy topics of interest to the Iranian government.
"Operators associated with this subgroup of Mint Sandstorm are patient and highly skilled social engineers whose tradecraft lacks many of the hallmarks that allow users to quickly identify phishing emails," Microsoft stated. "In some instances of this campaign, this subgroup also used legitimate but compromised accounts to send phishing lures."
The group has been active since at least 2013, has strong links to the Islamic Revolutionary Guard Corps (IRGC), and has not been directly involved in the cyber-operational aspect of the conflict between Israel and Hamas, according to cybersecurity firm CrowdStrike.
"Unlike in the Russia-Ukraine war, where known cyber operations have directly contributed to the conflict, those involved in the Israel-Hamas conflict have not directly contributed to Hamas military operations against Israel," the company stated in its "2024 Global Threat Report" released on Feb. 21.
These attacks usually start with spear-phishing and end with a combination of malware delivered to the target's system, according to an advisory from Volexity, which calls the group CharmingCypress. In September and October 2023, CharmingCypress used a number of typo-squatted domains addresses similar to legitimate domains to pose as officials from the International Institute of Iranian Studies (IIIS) to invite policy experts to a webinar. The initial email demonstrated the low-and-slow approach of CharmingCypress, eschewing any malicious link or attachment and inviting the targeted professional to reach out through other channels of communications, such as WhatsApp and Signal.
Using in-depth spearphishing, CharmingCypress aims to convince policy experts to install malware. Source: Volexity
The attacks target Middle East policy experts worldwide, with Volexity encountering a majority of attacks against European and US professionals, Adair says.
"They are quite aggressive," he says. "They'll even set up entire email chains or a phishing scenario where they're looking for comment and there's other people maybe three, four, or five people on that email thread with the exception of the target they're definitely trying to build rapport."
The long con eventually delivers a payload. Volexity identified five different malware families associated with the threat. The PowerLess backdoor is installed by the Windows version of the malware-laden virtual private network (VPN) application, which uses PowerShell to allow files to be transferred and executed, as well as targeting specific data on the system, logging keystrokes, and capturing screenshots. A macOS version of the malware is dubbed NokNok, while a separate malware chain using a RAR archive and LNK exploit leads to a backdoor named Basicstar.
The group's approach to social engineering definitely embodies the "persistence" piece of the advanced persistent threat (APT). Volexity sees a "constant barrage" of attacks, so policy experts have to become even more suspicious of cold contacts, Adair says.
Doing so will be difficult, as many policy experts are academics in constant contact with students or members of the public and are not used to being strict with their contacts, he says. Yet they should definitely think before opening documents or entering credentials into a site reached through an unknown link.
"At the end of the day, they have to get the person to click something or open something, which if I want you to review a paper or something like that, means ... being very wary of links and files," Adair says. "If I have to enter my credentials at any point in time, or authorize something that should be a major red flag. Similarly, if I'm being asked to download something, that should be a pretty big red flag."
In addition, policy experts need to understand that CharmingCypress will continue to target them even if its attempts fail, Volexity stated.
"This threat actor is highly committed to conducting surveillance on their targets in order to determine how best to manipulate them and deploy malware," the company stated in its advisory. "Additionally, few other threat actors have consistently churned out as many campaigns as CharmingCypress, dedicating human operators to support their ongoing efforts."
Originally posted here:
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets - Dark Reading
- Iran and Britain summon envoys over alleged spying in UK - BBC - May 19th, 2025 [May 19th, 2025]
- US and Iran Clash Over Nuclear Red Lines - Newsweek - May 19th, 2025 [May 19th, 2025]
- Witkoff says US red line in Iran talks is any ability for Tehran to enrich uranium - The Times of Israel - May 19th, 2025 [May 19th, 2025]
- Harvard University's alleged ties to Chinese paramilitary group, Iran-backed research spark GOP probe - Fox News - May 19th, 2025 [May 19th, 2025]
- Will Any New 'Nuclear Deal' Between the U.S. and Iran Be Worth The Paper It's Wr - Crude Oil Prices Today | OilPrice.com - May 19th, 2025 [May 19th, 2025]
- Iran, Azerbaijan hold military drill in disputed Nagorno-Karabakh: What to know - AL-Monitor - May 19th, 2025 [May 19th, 2025]
- Crude Oil Prices Supported by Dollar Weakness and Iran Nuclear Deal Doubts - Nasdaq - May 19th, 2025 [May 19th, 2025]
- Senior House Republicans question Harvard over Iran connections - Jewish Insider - May 19th, 2025 [May 19th, 2025]
- Trump 0.2 in Riyadh: Oil, arms, and a shadow over Iran - Tehran Times - May 19th, 2025 [May 19th, 2025]
- Witkoff: US red line in Iran talks is any ability for enrichment - The Times of Israel - May 19th, 2025 [May 19th, 2025]
- Minimums for a new Iran nuke deal, beware fake experts and other commentary - New York Post - May 19th, 2025 [May 19th, 2025]
- UK Plans New Powers to Tackle Rise in Iran-Backed Threats - Bloomberg - May 19th, 2025 [May 19th, 2025]
- 'Evil will not triumph': Witkoff pledges action against Hamas, Iran, calls for unity - The Jerusalem Post - May 19th, 2025 [May 19th, 2025]
- Iran Insists It Will Continue to Enrich Uranium With or Without a Nuclear Deal - Crude Oil Prices Today | OilPrice.com - May 19th, 2025 [May 19th, 2025]
- Marco Rubio warns Iran 'at the threshold' of nuclear weapon capability as US-Iran talks continue - Fox News - May 19th, 2025 [May 19th, 2025]
- New impasse? Iran rejects US demands to give up enrichment, says it will continue with or without deal - All Israel News - May 19th, 2025 [May 19th, 2025]
- Israeli suspected of spying on former PM Bennett on behalf of Iran - JNS.org - May 19th, 2025 [May 19th, 2025]
- Trump Wants an Iran Deal, but It May Be Weaker Than His Supporters Demand - The New York Times - May 17th, 2025 [May 17th, 2025]
- Iran says it will continue nuclear talks with the U.S., shrugging off Trumps threats - Los Angeles Times - May 17th, 2025 [May 17th, 2025]
- Iran says it will continue nuclear talks with the US, shrugging off Trumps threats - AP News - May 17th, 2025 [May 17th, 2025]
- Trump says Iran has a proposal from the US on its rapidly advancing nuclear program - AP News - May 17th, 2025 [May 17th, 2025]
- Trump says Iran wont be given time to build a nuclear weapon | Iran International - - May 17th, 2025 [May 17th, 2025]
- Iran Reaffirms Nuclear Rights Amid U.S. Warnings of 'Grave Risk' - kurdistan24.net - May 17th, 2025 [May 17th, 2025]
- Over 550 UK lawmakers urge proscription of Iran's IRGC as terrorist group - - May 17th, 2025 [May 17th, 2025]
- 'U.S. Must and Will Leave the Region,' Says Iran's Khamenei - kurdistan24.net - May 17th, 2025 [May 17th, 2025]
- Iran honors 2nd anniversary of 86th Naval Fleets global mission - Tehran Times - May 17th, 2025 [May 17th, 2025]
- Master negotiator who 'drowns the devil in words': Iran's man in nuclear talks with US - Ynetnews - May 17th, 2025 [May 17th, 2025]
- Iran says itll continue nuclear talks with US, shrugging off Trump threats - AP News - May 17th, 2025 [May 17th, 2025]
- Iran says it will continue nuclear talks with the US, shrugging off Trump's threats - The Daily Reflector - May 17th, 2025 [May 17th, 2025]
- Trump says Iran needs to move quickly on nuclear proposal - Reuters - May 17th, 2025 [May 17th, 2025]
- Iran's Khamenei: Trump 'lying when he speaks of peace' in region - The New Arab - May 17th, 2025 [May 17th, 2025]
- Iran says it will continue nuclear talks with the US, shrugging off Trump's threats - Citizen Tribune - May 17th, 2025 [May 17th, 2025]
- Three charged in UK with aiding Iranian intelligence, targeting Iran International - - May 17th, 2025 [May 17th, 2025]
- The Presidents Inbox Recap: The Iran Nuclear Talks - Council on Foreign Relations - May 17th, 2025 [May 17th, 2025]
- France & Iran Stars To Lead The Line For Inter Milan In Serie A Clash Vs Lazio - Yahoo Sports - May 17th, 2025 [May 17th, 2025]
- Spain, Germany, Russia, Iran, Sudan, Afghanistan, Lebanon, Venezuela and more Included in New US Travel Risk Update as Global Threat Levels Rise -... - May 17th, 2025 [May 17th, 2025]
- Trump says the US and Iran have sort of agreed on the terms for a nuclear deal - AP News - May 15th, 2025 [May 15th, 2025]
- Imposing Sanctions on China- and Iran-based Entities and Individuals that Support Irans Ballistic Missile Program - U.S. Department of State (.gov) - May 15th, 2025 [May 15th, 2025]
- Opinion | Trumps reversal on Iran may be his most consequential - The Washington Post - May 15th, 2025 [May 15th, 2025]
- Heres how a Trump nuclear deal with Iran could impact global oil supplies and prices - MarketWatch - May 15th, 2025 [May 15th, 2025]
- State Department confirms 'constructive' nuclear talks with Iran; Trump says deal 'sort of' agreed to - Fox News - May 15th, 2025 [May 15th, 2025]
- US targets Iran-backed Hezbollah with new sanctions, Treasury Departments says - Reuters - May 15th, 2025 [May 15th, 2025]
- Trump appeals for Qatars help in persuading Iran to give up its nuclear program - AP News - May 15th, 2025 [May 15th, 2025]
- Emerging nuclear agreement between US and Iran seems problematic, officials tell 'Post' - The Jerusalem Post - May 15th, 2025 [May 15th, 2025]
- Oil Extends Drop as Trump Says US Is Closer to Deal With Iran - Bloomberg.com - May 15th, 2025 [May 15th, 2025]
- Iran, European powers to hold nuclear talks in Turkey - Times of India - May 15th, 2025 [May 15th, 2025]
- Republicans urge Trump to follow through on his plan to dismantle Iran's nuclear capabilities - Fox News - May 15th, 2025 [May 15th, 2025]
- Trump Says US and Iran Close to Nuclear Deal - AllSides - May 15th, 2025 [May 15th, 2025]
- Iran is the most lonely country in the world right now, says KT McFarland - Fox Business - May 15th, 2025 [May 15th, 2025]
- Trump pulls sanctions on Syria, extends olive branch to Iran - The Washington Post - May 15th, 2025 [May 15th, 2025]
- WATCH: Trump urges Iran to take 'new and a better path' for nuclear deal in remarks at U.S.-Saudi investment forum - PBS - May 15th, 2025 [May 15th, 2025]
- Iran and Ethiopia have a security deal heres why they signed it - The Conversation - May 15th, 2025 [May 15th, 2025]
- Trump says Iran has sort of agreed to terms of nuclear deal - The Hill - May 15th, 2025 [May 15th, 2025]
- Trump says he doesnt want to make nuclear dust in Iran - Al Jazeera - May 15th, 2025 [May 15th, 2025]
- Iran Nuclear Deal Would Give a Little Boost to Global Oil Supply - Bloomberg.com - May 15th, 2025 [May 15th, 2025]
- Hailing Syria, arming Saudis, dealing with Iran and Houthis, Trump relegates Israeli concerns - The Times of Israel - May 15th, 2025 [May 15th, 2025]
- Trump is not an isolationist, he will stop Iran from getting a nuclear weapon, expert says - Fox News - May 15th, 2025 [May 15th, 2025]
- US says latest round of nuclear talks with Iran were 'encouraging' - BBC - May 11th, 2025 [May 11th, 2025]
- Iran's top diplomat arrives for indirect nuclear talks with US in Oman - ABC News - May 11th, 2025 [May 11th, 2025]
- Iran and the US conclude a 4th round of negotiations over Tehrans nuclear program in Oman - CNBC - May 11th, 2025 [May 11th, 2025]
- Iran and US begin 4th round of negotiations over Tehrans nuclear program in Oman - Politico - May 11th, 2025 [May 11th, 2025]
- U.S. "encouraged" by progress in fourth round of nuclear talks with Iran, official says - Axios - May 11th, 2025 [May 11th, 2025]
- Iran and US conclude a fourth round of negotiations over Tehrans nuclear program in Oman - AP News - May 11th, 2025 [May 11th, 2025]
- US and Iran agree to future nuclear talks as negotiations wrap up in Oman - France 24 - May 11th, 2025 [May 11th, 2025]
- Iran, US begin 4th round of talks in Oman, with focus on uranium enrichment - The Times of Israel - May 11th, 2025 [May 11th, 2025]
- NCRI Reveals Irans Secret Rainbow Facility Linked to Nuclear Weapons and Missile Program - National Council of Resistance of Iran - NCRI - May 11th, 2025 [May 11th, 2025]
- US and Iran hold fresh round of nuclear talks in Oman - France 24 - May 11th, 2025 [May 11th, 2025]
- Will the real Iran policy stand up? - Politico - May 11th, 2025 [May 11th, 2025]
- Iran eying closer tech cooperation with China, bypassing the West - analysis - The Jerusalem Post - May 11th, 2025 [May 11th, 2025]
- Iran vows not to back down from its nuclear rights, as talks with US set to resume - The Times of Israel - May 11th, 2025 [May 11th, 2025]
- US, Iran nuclear talks end with 'agreement' to move forward - www.israelhayom.com - May 11th, 2025 [May 11th, 2025]
- Five Signs of Growing Risk of US War With Iran - Newsweek - May 11th, 2025 [May 11th, 2025]
- Iran Sends Stark Warning to US: "Gates of Hell" - Newsweek - May 11th, 2025 [May 11th, 2025]
- Iran ready to respond decisively to any threat, military chief vows while inspecting Persian Gulf - Tehran Times - May 11th, 2025 [May 11th, 2025]
- Trump heads to Middle East amid Iran nuclear standoff and Gulf investment drive - The Jerusalem Post - May 11th, 2025 [May 11th, 2025]
- Iran's top diplomat arrives for indirect nuclear talks with US in Oman - MSN - May 11th, 2025 [May 11th, 2025]
- Iran is up to its old tricks - Israel National News - May 11th, 2025 [May 11th, 2025]
- U.S. Holds Fourth Round of Nuclear Talks With Iran in Oman Ahead of Trump's Mideast Trip - Haaretz - May 11th, 2025 [May 11th, 2025]
- The axis of illusion: How Russia and Iran are partnering to manipulate Trump - The Hill - May 11th, 2025 [May 11th, 2025]
- Reports: Iran pressed Houthis into truce with US to build momentum in nuclear talks - The Times of Israel - May 11th, 2025 [May 11th, 2025]