Threat Intelligence / Actor / APT35
APT35
As of 2026-06-10, APT35 is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt, ics scada. Also known as COBALT ILLUSION, Charming Kitten, ITG18, Mint Sandstorm. ATT&CK coverage spans 62 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1071 (Application Layer Protocol).
Also known as: COBALT ILLUSION, Charming Kitten, ITG18, Mint Sandstorm, Newscaster, Phosphorus, TA453, Magic Hound, APT42
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- T1071 Application Layer Protocol — Command and Control — observed in 3 of 3 tracked threats
- T1566 Phishing — Initial Access — observed in 3 of 3 tracked threats
- T1583 Acquire Infrastructure — Resource Development — observed in 3 of 3 tracked threats
- T1588 Obtain Capabilities — Resource Development — observed in 3 of 3 tracked threats
- T1589 Gather Victim Identity Information — Reconnaissance — observed in 3 of 3 tracked threats
- T1005 Data from Local System — Collection — observed in 2 of 3 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 2 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- T1046 Network Service Discovery — Discovery — observed in 2 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Execution — observed in 2 of 3 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 2 of 3 tracked threats
- T1082 System Information Discovery — Discovery — observed in 2 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Control — observed in 2 of 3 tracked threats
Tracked threats
- Iranian "Dream Job" Campaign (TA455 / Charming Kitten) — SnailResin Loader & SlugResin Backdoor Targeting Aerospace, Aviation & Defense — HIGH
- APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting — CRITICAL
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026) — CRITICAL
Related CVEs
CVE-2024-23897, CVE-2024-21893, CVE-2024-21887, CVE-2024-1709, CVE-2024-1708, CVE-2023-7028, CVE-2023-22527, CVE-2021-22205, CVE-2019-18935, CVE-2017-3506, CVE-2017-11317, CVE-2012-1823
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →