CHARMING KITTEN

Oct. 4, 2024, 12:41 p.m.

Description

Since June 2024, the Iran-nexus actor CHARMING KITTEN has been creating new network infrastructure for credential phishing, targeting individuals perceived as threats to the Iranian regime. The actor's infrastructure, known as Cluster B, uses domains with specific characteristics like similar TLDs, hyphenated naming conventions, and shared IP addresses. While specific targets for the new domains are unknown, previous targets included researchers, journalists, NGO leaders, and human rights activists. The phishing pages often mimic login interfaces for popular services like Google and YouTube, distributed through spear-phishing emails disguised as conference invitations or links to legitimate documents.

Date

Published Created Modified
Oct. 4, 2024, 10:16 a.m. Oct. 4, 2024, 10:16 a.m. Oct. 4, 2024, 12:41 p.m.

Attack Patterns

CHARMING KITTEN

T1585

T1589

T1586

T1566.002

T1584

T1566

Additional Informations

Media

Education

NGO

Government

Iran, Islamic Republic of

Israel

United States of America