Threat Intelligence / Actor / APT35

APT35

As of 2026-06-10, APT35 is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt, ics scada. Also known as COBALT ILLUSION, Charming Kitten, ITG18, Mint Sandstorm. ATT&CK coverage spans 62 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1071 (Application Layer Protocol).

Nation: Iran · 3 tracked threat(s) · Categories: APT, ICS_SCADA

Also known as: COBALT ILLUSION, Charming Kitten, ITG18, Mint Sandstorm, Newscaster, Phosphorus, TA453, Magic Hound, APT42

ATT&CK techniques observed

62 techniques observed across 3 of 3 tracked threats · Command and Control (7), Impact (7), Discovery (6), Reconnaissance (6), Stealth (formerly Defense Evasion) (6), Collection (4)

Tracked threats

Related CVEs

12 CVEs referenced by tracked APT35 activity

CVE-2024-23897, CVE-2024-21893, CVE-2024-21887, CVE-2024-1709, CVE-2024-1708, CVE-2023-7028, CVE-2023-22527, CVE-2021-22205, CVE-2019-18935, CVE-2017-3506, CVE-2017-11317, CVE-2012-1823

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence