APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting
APT35 (Charming Kitten) GCC Pre-Positioning Cyber (TL-2026-0339), also tracked as Operation Swiftstrike, is a critical-severity advanced persistent threat campaign, first published 2026-04-09. It is attributed to APT35 (Iran) with high confidence, affects ConnectWise ScreenConnect, references 12 CVEs (CVE-2024-1708, CVE-2024-1709, CVE-2024-21893), maps to 40 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-0339
- Threat ID
- TL-2026-0339
- Also known as
- Operation Swiftstrike, Operation Desert Breach, Operation Shattered Mirror, GCC Pre-Positioning Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-04-09
- Last reviewed
- 2026-04-09
- Attribution
- APT35
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- government, critical-infrastructure, defense, energy, water, education, legal, financial, telecommunications, aviation, healthcare
- Target regions
- Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, Israel, Turkey, Oman, Azerbaijan
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in APT35 (Charming Kitten) GCC Pre-Positioning Cyber
Malware and tooling: RTM Project RAT, WezRAT, Nuclei, RouterScan, Sliver - S0633, Sliver C2, sqlmap - S0225
Iran-linked APT35 (Charming Kitten), an IRGC-affiliated threat group, conducted years of systematic cyber reconnaissance and pre-positioning across GCC nations including UAE, Saudi Arabia, Qatar, Kuwait, and Bahrain. The pre-positioned access directly enabled targeting data for Iran's coordinated missile and drone strikes against seven nations following Operation Epic Fury on February 28, 2026, demonstrating a dangerous convergence of cyber and kinetic warfare.
How APT35 (Charming Kitten) GCC Pre-Positioning Cyber works
APT35, also tracked as Charming Kitten, Phosphorus, Mint Sandstorm, TA453, Magic Hound, COBALT ILLUSION, and ITG18, is an Iranian state-sponsored cyber espionage group affiliated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). Active since at least 2011, the group has evolved from basic phishing operations into a sophisticated multi-division offensive cyber unit capable of long-term infrastructure compromise and intelligence preparation of the environment (IPE).
In a groundbreaking report published April 9, 2026, CloudSEK's TRIAD research team documented how APT35 systematically pre-positioned itself across critical infrastructure networks in Gulf Cooperation Council (GCC) nations over a multi-year campaign. This pre-positioning served a dual purpose: traditional espionage and — critically — the generation of targeting intelligence that directly supported Iran's kinetic military operations following Operation Epic Fury.
Operation Epic Fury, launched by the United States and Israel on February 28, 2026, struck Iranian nuclear infrastructure, ballistic missile production facilities, and IRGC compounds across 24 provinces. Iran responded with a multi-day ballistic missile and Shahed drone campaign targeting seven nations: Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, and Israel. CloudSEK's analysis reveals that APT35's pre-positioned access across these same nations provided critical targeting data — infrastructure maps, network topologies, and operational intelligence — that enabled precision targeting of critical facilities.
The campaign leveraged multiple attack vectors. APT35 exploited recently disclosed vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1708/CVE-2024-1709), Ivanti Connect Secure (CVE-2024-21893/CVE-2024-21887), Telerik UI (CVE-2019-18935/CVE-2017-11317), PHP-CGI (CVE-2012-1823), and other enterprise platforms, often achieving exploitation within 48 hours of CVE disclosure. Their toolset included custom malware such as the RTM Project RAT (a modular Remote Access Trojan with Active Directory integration), WezRAT infostealer, and commodity tools including Nuclei, RouterScan, SQLMap, and Acunetix.
A late 2025 leak of APT35's internal operational documents by CloudSEK revealed a 17-member operational structure organized into four divisions: Operations Command, Project Managers, Specialized Operators, and Generic Operators. The leak exposed C2 infrastructure, operational playbooks, and evidence of massive data exfiltration — including 74 GB from a single Jordanian legal target and 6,911 emails from Afghan government ministries. Despite this exposure, APT35 rapidly refreshed infrastructure and remained operational.
Confirmed sub-campaigns include Operation Shattered Mirror (Israel, mass surveillance via compromised routers), Operation Desert Breach (Jordan, government and legal sector compromise), and Operation Swiftstrike (multi-country ConnectWise/Ivanti exploitation targeting Turkey, Saudi Arabia, Jordan, and UAE). The group's activities across GCC nations constitute the most significant documented case of cyber operations directly enabling kinetic military targeting, representing a paradigm shift in hybrid warfare.
MITRE ATT&CK techniques used in TL-2026-0339
credential-access
T1003 OS Credential Dumping; T1110 Brute Force; T1539 Steal Web Session Cookie
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection
discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1482 Domain Trust Discovery
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling; T1573 Encrypted Channel
persistence
T1136 Create Account; T1505 Server Software Component; T1547 Boot or Logon Autostart Execution
initial-access
T1190 Exploit Public-Facing Application; T1566 Phishing
impact
T1486 Data Encrypted for Impact
resource-development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1591 Gather Victim Org Information; T1592 Gather Victim Host Information; T1595 Active Scanning
defense-impairment
Affected products and versions in APT35 (Charming Kitten) GCC Pre-Positioning Cyber
- ConnectWise — ScreenConnect
Vulnerable versions: All versions before 23.9.8
Fixed in: 23.9.8+ - Ivanti — Connect Secure
Vulnerable versions: 9.x, 22.x before patch
Fixed in: Patched versions per advisory - Progress Software — Telerik UI for ASP.NET AJAX
Vulnerable versions: Multiple versions
Fixed in: Patched versions - PHP Group — PHP-CGI
Vulnerable versions: 5.3.x and earlier
Fixed in: 5.4+ - Atlassian — Confluence Server
Vulnerable versions: Multiple versions
Fixed in: Patched per CVE-2023-22527 - GitLab — GitLab CE/EE
Vulnerable versions: Multiple versions
Fixed in: Patched per CVE-2023-7028 - Jenkins — Jenkins
Vulnerable versions: Before 2.442, LTS before 2.426.3
Fixed in: 2.442+, LTS 2.426.3+ - Oracle — WebLogic Server
Vulnerable versions: 10.3.6.0, 12.1.3.0, 12.2.1.1, 12.2.1.2
Fixed in: Patched per CVE-2017-3506
Remediation for APT35 (Charming Kitten) GCC Pre-Positioning Cyber
Patches
- Apply ConnectWise ScreenConnect patches for CVE-2024-1708 and CVE-2024-1709
- Apply Ivanti Connect Secure patches for CVE-2024-21893 and CVE-2024-21887
- Apply Telerik UI patches for CVE-2019-18935 and CVE-2017-11317
- Apply Atlassian Confluence patches for CVE-2023-22527
- Apply GitLab patches for CVE-2023-7028 and CVE-2021-22205
- Apply Jenkins patches for CVE-2024-23897
- Upgrade all PHP installations to mitigate CVE-2012-1823
Immediate actions
- Block known APT35 C2 IP addresses at perimeter firewalls (185.141.63.55 and associated infrastructure)
- Hunt for web shells across internet-facing servers, especially in IIS/ASP.NET and PHP environments
- Review VPN and remote access logs for anomalous connections from Iranian IP ranges
- Enable enhanced monitoring on all ConnectWise ScreenConnect and Ivanti Connect Secure instances
- Audit domain admin accounts and service accounts for unauthorized additions
- Block known APT35 domains (sunrapid.com, lydston.com, aecars.store) at DNS and proxy layers
Workarounds
- Restrict external access to management interfaces for ConnectWise, Ivanti, and Telerik products
- Implement geoblocking for connections originating from Iranian IP space where operationally feasible
- Disable unnecessary remote access services and limit VPN access to required personnel only
- Enable audit logging on all domain controllers and critical servers
Longer-term hardening
- Deploy EDR with behavioral detection focused on PowerShell-based backdoors and lateral movement
- Implement network segmentation between IT and OT/SCADA environments
- Deploy SIEM rules for APT35 TTPs including web shell deployment, credential dumping, and large-volume data exfiltration
- Establish threat hunting cadence focused on Iranian APT indicators
- Implement phishing-resistant MFA across all remote access and privileged accounts
- Conduct tabletop exercises simulating hybrid cyber-kinetic attack scenarios
CVEs associated with APT35 (Charming Kitten) GCC Pre-Positioning Cyber
CVE-2024-1708, CVE-2024-1709, CVE-2024-21893, CVE-2024-21887, CVE-2019-18935, CVE-2017-11317, CVE-2012-1823, CVE-2023-22527, CVE-2023-7028, CVE-2021-22205, CVE-2024-23897, CVE-2017-3506
Weaknesses (CWE) in APT35 (Charming Kitten) GCC Pre-Positioning Cyber
CWE-287, CWE-918, CWE-502, CWE-434, CWE-78, CWE-89, CWE-22, CWE-269
Timeline of APT35 (Charming Kitten) GCC Pre-Positioning Cyber
- APT35/Charming Kitten first identified as an active Iranian state-sponsored threat group affiliated with IRGC-IO
- Operation Afghan Infiltration begins — APT35 targets Afghan telecommunications systems and government ministries, exfiltrating 6,911 emails
- Operation Shattered Mirror launched targeting Israel with mass surveillance via compromised routers and commercial website credential harvesting
- APT35 achieves day-1 exploitation of ConnectWise ScreenConnect vulnerabilities (CVE-2024-1708/CVE-2024-1709), launching Operation Swiftstrike across Turkey, Saudi Arabia, Jordan, and UAE
- Operation Desert Breach escalates with compromise of Jordanian Ministry of Justice, academic institutions, and law firms; 74 GB exfiltrated from single legal target
- APT35 exploits Ivanti Connect Secure vulnerabilities (CVE-2024-21893/CVE-2024-21887) for VPN infrastructure compromise across GCC targets
- APT35 pre-positioning across GCC critical infrastructure networks intensifies — persistent access established in UAE, Saudi Arabia, Qatar, Kuwait, and Bahrain
- CloudSEK TRIAD team discovers and analyzes leaked APT35 internal operational documents on GitHub, exposing 17-member team structure, C2 infrastructure, and operational playbooks
- Operation Epic Fury launched by US/Israel targeting Iranian nuclear infrastructure, IRGC compounds across 24 provinces; triggers Iranian kinetic retaliation using APT35-gathered targeting data
- Iran launches multi-day ballistic missile and Shahed drone campaign against 7 nations (Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, Israel), enabled by APT35 cyber pre-positioning intelligence
- Iranian APT groups including APT35, MuddyWater, APT33, APT34, and 60+ hacktivist proxies activate coordinated cyber campaign targeting GCC, Israel, and US infrastructure
- CISA publishes advisory AA26-097A warning of Iranian-affiliated actors exploiting PLCs across US critical infrastructure sectors including water, energy, and government
- CloudSEK publishes 'Kitten Had the Map All Along' report documenting APT35's GCC pre-positioning campaign and its direct link to kinetic military targeting
- As of 2026-05-29, APT35/Charming Kitten remains an active, undeterred IRGC threat: its Nimbus Manticore subgroup is reported continuing operations after the Feb-May Operation Epic Fury campaign, and CISA advisory AA26-097A (Apr 7) still warns of ongoing Iranian APT critical-infrastructure exploitation. The shaky ceasefire has not halted cyber activity; no takedown or arrests reported.
Sources cited for APT35 (Charming Kitten) GCC Pre-Positioning Cyber
- CloudSEK: Kitten Had the Map All Along — Raising GCC Tensions & The Pre-Positioning Map
- CloudSEK Full Research PDF: The Pre-Positioning Map
- CloudSEK: An Insider Look at the IRGC-linked APT35 Operations
- Gatewatcher: Data Breach — The Operations of Charming Kitten Revealed
- LevelBlue SpiderLabs: Operation Epic Fury — From Regional Escalation to Global Cyber Risk
- AttackIQ: Defending Against Iranian Cyber Threats in the Wake of Operation Epic Fury
- Tenable: Operation Epic Fury — Potential Iranian Cyber Counteroffensive Operations
- Hunt.io: Iranian APT Infrastructure in Focus — Mapping State-Aligned Clusters
- MITRE ATT&CK: Magic Hound (G0059)
- Darktrace: APT35 Charming Kitten Discovered in Pre-Infected Environment
- CISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure
- Malpedia: APT35 Threat Actor Profile
Threats related to APT35 (Charming Kitten) GCC Pre-Positioning Cyber
- Laravel Livewire Unauthenticated RCE via Synthesizer Smuggling — MuddyWater Active Exploitation (CVE-2025-54068)
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)
- BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere Infrastructure
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access
- APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting
- ConnectWise ScreenConnect Path Traversal (CVE-2024-1708) Added to CISA KEV — Storm-1175 / Medusa Ransomware Active Exploitation
Detection coverage for TL-2026-0339
As of 2026-04-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0339 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.