Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets – Dark Reading
Conflicts in the Middle East, Ukraine, and other areas of simmering geopolitical tensions have made policy experts the latest target of cyber operations conducted by state-sponsored groups.
An Iran-linked group known as Charming Kitten, CharmingCypress, and APT42 recently targeted Middle East policy experts in the region as well as in the US and Europe, using a phony webinar platform to compromise its targeted victims, incident response services firm Volexity stated in an advisory published this month.
Charming Kitten is well known for its extensive social engineering tactics, including low-and-slow social engineering attacks against think tanks and journalists to gather political intelligence, the firm stated.
The group often dupes is targets into installing Trojan-rigged VPN applications to gain access to the fake webinar platform and other sites, resulting in the installation of malware. Overall, the group has embraced the long confidence game, says Steven Adair, co-founder and president of Volexity.
"I don't know if that is necessarily sophisticated and advanced, but it is a lot of effort," he says. "It's more advanced and more sophisticated than your average attack by a significant margin. It's a level of effort and dedication ... that is definitely different and uncommon ... to go to that much effort for such a specific set of attacks."
Policy experts are a frequently targeted by nation-state groups. The Russia-linked ColdRiver group, for example, has targeted nongovernmental organizations, military officers, and other experts using social engineering to gain the confidence of the victim and then following up with a malicious link or malware. In Jordan, targeted exploitation reportedly by government agencies used the Pegasus spyware program developed by the NSO Group and targeted journalists, digital-rights lawyers, and other policy experts.
Other companies have also described Charming Kitten/CharmingCypress' tactics. In a January advisory, Microsoft warned that the group, which it calls Mint Sandstorm, had targeted journalists, researchers, professors, and other experts covering security and policy topics of interest to the Iranian government.
"Operators associated with this subgroup of Mint Sandstorm are patient and highly skilled social engineers whose tradecraft lacks many of the hallmarks that allow users to quickly identify phishing emails," Microsoft stated. "In some instances of this campaign, this subgroup also used legitimate but compromised accounts to send phishing lures."
The group has been active since at least 2013, has strong links to the Islamic Revolutionary Guard Corps (IRGC), and has not been directly involved in the cyber-operational aspect of the conflict between Israel and Hamas, according to cybersecurity firm CrowdStrike.
"Unlike in the Russia-Ukraine war, where known cyber operations have directly contributed to the conflict, those involved in the Israel-Hamas conflict have not directly contributed to Hamas military operations against Israel," the company stated in its "2024 Global Threat Report" released on Feb. 21.
These attacks usually start with spear-phishing and end with a combination of malware delivered to the target's system, according to an advisory from Volexity, which calls the group CharmingCypress. In September and October 2023, CharmingCypress used a number of typo-squatted domains addresses similar to legitimate domains to pose as officials from the International Institute of Iranian Studies (IIIS) to invite policy experts to a webinar. The initial email demonstrated the low-and-slow approach of CharmingCypress, eschewing any malicious link or attachment and inviting the targeted professional to reach out through other channels of communications, such as WhatsApp and Signal.
Using in-depth spearphishing, CharmingCypress aims to convince policy experts to install malware. Source: Volexity
The attacks target Middle East policy experts worldwide, with Volexity encountering a majority of attacks against European and US professionals, Adair says.
"They are quite aggressive," he says. "They'll even set up entire email chains or a phishing scenario where they're looking for comment and there's other people maybe three, four, or five people on that email thread with the exception of the target they're definitely trying to build rapport."
The long con eventually delivers a payload. Volexity identified five different malware families associated with the threat. The PowerLess backdoor is installed by the Windows version of the malware-laden virtual private network (VPN) application, which uses PowerShell to allow files to be transferred and executed, as well as targeting specific data on the system, logging keystrokes, and capturing screenshots. A macOS version of the malware is dubbed NokNok, while a separate malware chain using a RAR archive and LNK exploit leads to a backdoor named Basicstar.
The group's approach to social engineering definitely embodies the "persistence" piece of the advanced persistent threat (APT). Volexity sees a "constant barrage" of attacks, so policy experts have to become even more suspicious of cold contacts, Adair says.
Doing so will be difficult, as many policy experts are academics in constant contact with students or members of the public and are not used to being strict with their contacts, he says. Yet they should definitely think before opening documents or entering credentials into a site reached through an unknown link.
"At the end of the day, they have to get the person to click something or open something, which if I want you to review a paper or something like that, means ... being very wary of links and files," Adair says. "If I have to enter my credentials at any point in time, or authorize something that should be a major red flag. Similarly, if I'm being asked to download something, that should be a pretty big red flag."
In addition, policy experts need to understand that CharmingCypress will continue to target them even if its attempts fail, Volexity stated.
"This threat actor is highly committed to conducting surveillance on their targets in order to determine how best to manipulate them and deploy malware," the company stated in its advisory. "Additionally, few other threat actors have consistently churned out as many campaigns as CharmingCypress, dedicating human operators to support their ongoing efforts."
Originally posted here:
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets - Dark Reading
- Trump says he thinks Iran's new supreme leader is alive but 'damaged' - Reuters - March 13th, 2026 [March 13th, 2026]
- The Iran War Has Four Stages. Were in the Second. - The Atlantic - March 13th, 2026 [March 13th, 2026]
- Americans on Iran strikes: 'What if this turns into a forever war?' - BBC - March 13th, 2026 [March 13th, 2026]
- This military rebel group could join the Iran war next against the U.S. - Axios - March 13th, 2026 [March 13th, 2026]
- 'There's no hiding place on a ship': The sailors stranded near Iran - BBC - March 13th, 2026 [March 13th, 2026]
- War in Iran Has India Wondering How to Keep Its Stovetops Lit - The New York Times - March 13th, 2026 [March 13th, 2026]
- How do other countries view the U.S. and Israel's war with Iran? - CBS News - March 13th, 2026 [March 13th, 2026]
- Iran Is Laying Mines in the Strait of Hormuz, U.S. Officials Say - The New York Times - March 13th, 2026 [March 13th, 2026]
- What we know on the 14th day of the US and Israels war with Iran - CNN - March 13th, 2026 [March 13th, 2026]
- Trump says not appropriate for Iran to participate in the World Cup in US - Al Jazeera - March 13th, 2026 [March 13th, 2026]
- What Is the Strait of Hormuz and Why Is Iran Blocking It? - The New York Times - March 13th, 2026 [March 13th, 2026]
- Iran pushes back after Trump says team shouldn't participate in World Cup 'for their own life and safety' - Yahoo Sports - March 13th, 2026 [March 13th, 2026]
- Trump may be unable to end the war he started with Iran, even if he wanted to - CNN - March 13th, 2026 [March 13th, 2026]
- How the War in Iran Could Help China and Change Asia - The New York Times - March 13th, 2026 [March 13th, 2026]
- Iran Shocks Could Spur a Shift to Clean Energy But Also to Coal - The New York Times - March 13th, 2026 [March 13th, 2026]
- US temporarily lifts sanctions on Russian oil at sea as Iran war sees global prices surge - The Guardian - March 13th, 2026 [March 13th, 2026]
- Democrats ask Pentagon about Iran school strike and role of AI - NBC News - March 13th, 2026 [March 13th, 2026]
- Trump threatens Iran following a new wave of attacks on the Gulf states and Israel - NBC 5 Dallas-Fort Worth - March 13th, 2026 [March 13th, 2026]
- Fallout From Iran War and Oil Shock Deliver Another Blow to World Economy - The New York Times - March 13th, 2026 [March 13th, 2026]
- Iran says its new leader made his 1st address, vowing to keep Strait of Hormuz closed - NPR - March 13th, 2026 [March 13th, 2026]
- Iran vows to fight on in first message issued in name of Mojtaba Khamenei - The Guardian - March 13th, 2026 [March 13th, 2026]
- Iran war is the largest oil supply disruption in history, report finds - Politico - March 13th, 2026 [March 13th, 2026]
- US and allies clash with Russia and China at UN over Iran nuclear program - Reuters - March 13th, 2026 [March 13th, 2026]
- The biggest Iran polling takeaway: Americans dont see the point of this war - CNN - March 13th, 2026 [March 13th, 2026]
- The war in Iran is an American failure. What do we do now? | Robert Reich - The Guardian - March 13th, 2026 [March 13th, 2026]
- We asked 1,000 Americans if U.S. strikes on Iran should continue. Heres what they said. - The Washington Post - March 13th, 2026 [March 13th, 2026]
- The Guardian view on the cost of Trumps war on Iran: the worlds poor will pay most dearly | Editorial - The Guardian - March 13th, 2026 [March 13th, 2026]
- Does President Trump have an exit strategy for the war with Iran? - Al Jazeera - March 13th, 2026 [March 13th, 2026]
- Expert says Iran drone attack on California coast would be 'very easy' to stop - Fox Business - March 13th, 2026 [March 13th, 2026]
- Stryker Cyberattack Adds to Fears of New Front in Iran War - The New York Times - March 13th, 2026 [March 13th, 2026]
- How Lindsey Graham got Trump to yes on Iran - Politico - March 4th, 2026 [March 4th, 2026]
- How the Bombing of Iran Is Affecting Lebanon, Kuwait and Other Countries - The New York Times - March 4th, 2026 [March 4th, 2026]
- In maps: Strikes across Iran and the Middle East - BBC - March 4th, 2026 [March 4th, 2026]
- Israel strikes Tehran and Beirut as Iran vows complete destruction in region - The Guardian - March 4th, 2026 [March 4th, 2026]
- IRGC says Iran in complete control of Strait of Hormuz amid Trump threats - Al Jazeera - March 4th, 2026 [March 4th, 2026]
- Iran strikes risk more voter frustration on the economy with rising gas prices - NBC News - March 4th, 2026 [March 4th, 2026]
- Hegseth, Caine preview major gravity-bombing campaign on Iran - The Hill - March 4th, 2026 [March 4th, 2026]
- Why a Democratic Congressman Is Supporting Trumps War with Iran - The New Yorker - March 4th, 2026 [March 4th, 2026]
- Everything we know on the fifth day of the US and Israels war with Iran - CNN - March 4th, 2026 [March 4th, 2026]
- Goldman's David Solomon surprised by benign market reaction to Iran war - CNBC - March 4th, 2026 [March 4th, 2026]
- After the strike: The danger of war in Iran - Brookings - March 4th, 2026 [March 4th, 2026]
- Hegseth: Iran is toast, and the US and Israel will rain down death and destruction - The Times of Israel - March 4th, 2026 [March 4th, 2026]
- How the US-Israeli war on Iran created a massive hole in global airspace - The Guardian - March 4th, 2026 [March 4th, 2026]
- Iran Is Shooting at Some of the Worlds Busiest Airports - WSJ - March 2nd, 2026 [March 2nd, 2026]
- Trump says there will likely be more US deaths as Iran strikes to continue until all goals achieved - BBC - March 2nd, 2026 [March 2nd, 2026]
- War widens as Israeli and US planes pound Iran and Tehran and its proxies hit back - AP News - March 2nd, 2026 [March 2nd, 2026]
- Pete Hegseth claims Trump is finishing war with Iran as conflict widens; fourth US service member confirmed killed US politics live - The Guardian - March 2nd, 2026 [March 2nd, 2026]
- Opinion | How to Think About Trumps War With Iran - The New York Times - March 2nd, 2026 [March 2nd, 2026]
- What we know about the widening US war with Iran, as conflict enters third day - CNN - March 2nd, 2026 [March 2nd, 2026]
- Map shows attack locations across Iran, including the capital and the site of a major nuclear facility - CBS News - March 2nd, 2026 [March 2nd, 2026]
- Trumps Attack on Iran Puts Him on Shakier Legal Ground Than Before - Politico - March 2nd, 2026 [March 2nd, 2026]
- Iran conflict: Where things stand, global responses and what comes next - CNBC - March 2nd, 2026 [March 2nd, 2026]
- Hegseth leaves door open for boots on the ground in Iran - The Hill - March 2nd, 2026 [March 2nd, 2026]
- The Costs of the Strikes on Iran - The New York Times - March 2nd, 2026 [March 2nd, 2026]
- US and Israel pound Iran as Trump signals willingness to talk to new leaders after Khamenei's death - AP News - March 2nd, 2026 [March 2nd, 2026]
- The Iran war exposes the limits of Russias leverage in a fragmenting regional order - Chatham House - March 2nd, 2026 [March 2nd, 2026]
- Democrats thrown into disarray as US offensive on Iran creates cracks - The Guardian - March 2nd, 2026 [March 2nd, 2026]
- Trump Says More U.S. Casualties Are Likely in War With Iran, and Oil Prices Jump After Attack - The New York Times - March 2nd, 2026 [March 2nd, 2026]
- British Base Hit in Cyprus, U.K. Terror Threat Under Review as Iran War Spreads - Time Magazine - March 2nd, 2026 [March 2nd, 2026]
- Higher gas prices are likely coming to the pump after oil prices jump in wake of U.S. strikes in Iran - NBC News - March 2nd, 2026 [March 2nd, 2026]
- How the Assault on Iran Unfolded - The New York Times - March 2nd, 2026 [March 2nd, 2026]
- Hegseth: US didnt start war with Iran, but we are finishing it - Al Jazeera - March 2nd, 2026 [March 2nd, 2026]
- Pete Hegseth says Iran military mission is "laser-focused" and it will not be "endless" - CBS News - March 2nd, 2026 [March 2nd, 2026]
- Photos: U.S.-Israeli strikes in Iran and reactions from around the world - NPR - March 2nd, 2026 [March 2nd, 2026]
- Lack of a clear Iran plan could suck US into a long conflict: Where does this go? - The Guardian - March 2nd, 2026 [March 2nd, 2026]
- Warships, explosive drones and stealth bombers: The high-tech weapons and hardware the US is using to attack Iran - CNN - March 2nd, 2026 [March 2nd, 2026]
- Stocks fall and oil surges as war with Iran spreads - CNN - March 2nd, 2026 [March 2nd, 2026]
- Spain denies US permission to use jointly operated bases to attack Iran - The Guardian - March 2nd, 2026 [March 2nd, 2026]
- White House official: Iran's 'new potential leadership' suggests it's open to talks and Trump says he's 'eventually' willing - PBS - March 2nd, 2026 [March 2nd, 2026]
- Hundreds of thousands of travelers stranded following U.S.-Israel attacks on Iran - PBS - March 2nd, 2026 [March 2nd, 2026]
- Iran conflict is Trumps hour of reckoning on many fronts - MS NOW - March 2nd, 2026 [March 2nd, 2026]
- Hegseth insists the Iran conflict is not endless and declares, We fight to win - AP News - March 2nd, 2026 [March 2nd, 2026]
- Prediction markets scrutinised over Iran bets - Reuters - March 2nd, 2026 [March 2nd, 2026]
- US and Iran to hold talks as pressure for nuclear deal builds - BBC - February 26th, 2026 [February 26th, 2026]
- Trump risks walking into an Iraq-style trap in Iran - CNN - February 26th, 2026 [February 26th, 2026]
- A Deal or War? Crucial Talks to Begin Between U.S. and Iran - The New York Times - February 26th, 2026 [February 26th, 2026]
- Most Americans see Iran as an enemy but doubt Trump's judgment on military force, AP-NORC poll finds - AP News - February 26th, 2026 [February 26th, 2026]
- Middle East travel warnings expanded as tensions between US and Iran increase - The Guardian - February 26th, 2026 [February 26th, 2026]
- US issues new Iran sanctions on eve of nuclear talks in Geneva - Al Jazeera - February 26th, 2026 [February 26th, 2026]
- Maps: Where the U.S. Is Building Up Military Force Near Iran - The New York Times - The New York Times - February 26th, 2026 [February 26th, 2026]