APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting

APT35 (Charming Kitten) GCC Pre-Positioning Cyber (TL-2026-0339), also tracked as Operation Swiftstrike, is a critical-severity advanced persistent threat campaign, first published 2026-04-09. It is attributed to APT35 (Iran) with high confidence, affects ConnectWise ScreenConnect, references 12 CVEs (CVE-2024-1708, CVE-2024-1709, CVE-2024-21893), maps to 40 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0339

Threat ID
TL-2026-0339
Also known as
Operation Swiftstrike, Operation Desert Breach, Operation Shattered Mirror, GCC Pre-Positioning Campaign
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-04-09
Last reviewed
2026-04-09
Attribution
APT35
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
government, critical-infrastructure, defense, energy, water, education, legal, financial, telecommunications, aviation, healthcare
Target regions
Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, Israel, Turkey, Oman, Azerbaijan
Detection rules
9
Indicators of compromise
20

Malware and tooling in APT35 (Charming Kitten) GCC Pre-Positioning Cyber

Malware and tooling: RTM Project RAT, WezRAT, Nuclei, RouterScan, Sliver - S0633, Sliver C2, sqlmap - S0225

Iran-linked APT35 (Charming Kitten), an IRGC-affiliated threat group, conducted years of systematic cyber reconnaissance and pre-positioning across GCC nations including UAE, Saudi Arabia, Qatar, Kuwait, and Bahrain. The pre-positioned access directly enabled targeting data for Iran's coordinated missile and drone strikes against seven nations following Operation Epic Fury on February 28, 2026, demonstrating a dangerous convergence of cyber and kinetic warfare.

How APT35 (Charming Kitten) GCC Pre-Positioning Cyber works

APT35, also tracked as Charming Kitten, Phosphorus, Mint Sandstorm, TA453, Magic Hound, COBALT ILLUSION, and ITG18, is an Iranian state-sponsored cyber espionage group affiliated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). Active since at least 2011, the group has evolved from basic phishing operations into a sophisticated multi-division offensive cyber unit capable of long-term infrastructure compromise and intelligence preparation of the environment (IPE).

In a groundbreaking report published April 9, 2026, CloudSEK's TRIAD research team documented how APT35 systematically pre-positioned itself across critical infrastructure networks in Gulf Cooperation Council (GCC) nations over a multi-year campaign. This pre-positioning served a dual purpose: traditional espionage and — critically — the generation of targeting intelligence that directly supported Iran's kinetic military operations following Operation Epic Fury.

Operation Epic Fury, launched by the United States and Israel on February 28, 2026, struck Iranian nuclear infrastructure, ballistic missile production facilities, and IRGC compounds across 24 provinces. Iran responded with a multi-day ballistic missile and Shahed drone campaign targeting seven nations: Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, and Israel. CloudSEK's analysis reveals that APT35's pre-positioned access across these same nations provided critical targeting data — infrastructure maps, network topologies, and operational intelligence — that enabled precision targeting of critical facilities.

The campaign leveraged multiple attack vectors. APT35 exploited recently disclosed vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1708/CVE-2024-1709), Ivanti Connect Secure (CVE-2024-21893/CVE-2024-21887), Telerik UI (CVE-2019-18935/CVE-2017-11317), PHP-CGI (CVE-2012-1823), and other enterprise platforms, often achieving exploitation within 48 hours of CVE disclosure. Their toolset included custom malware such as the RTM Project RAT (a modular Remote Access Trojan with Active Directory integration), WezRAT infostealer, and commodity tools including Nuclei, RouterScan, SQLMap, and Acunetix.

A late 2025 leak of APT35's internal operational documents by CloudSEK revealed a 17-member operational structure organized into four divisions: Operations Command, Project Managers, Specialized Operators, and Generic Operators. The leak exposed C2 infrastructure, operational playbooks, and evidence of massive data exfiltration — including 74 GB from a single Jordanian legal target and 6,911 emails from Afghan government ministries. Despite this exposure, APT35 rapidly refreshed infrastructure and remained operational.

Confirmed sub-campaigns include Operation Shattered Mirror (Israel, mass surveillance via compromised routers), Operation Desert Breach (Jordan, government and legal sector compromise), and Operation Swiftstrike (multi-country ConnectWise/Ivanti exploitation targeting Turkey, Saudi Arabia, Jordan, and UAE). The group's activities across GCC nations constitute the most significant documented case of cyber operations directly enabling kinetic military targeting, representing a paradigm shift in hybrid warfare.

MITRE ATT&CK techniques used in TL-2026-0339

credential-access

T1003 OS Credential Dumping; T1110 Brute Force; T1539 Steal Web Session Cookie

collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1482 Domain Trust Discovery

lateral-movement

T1021 Remote Services; T1570 Lateral Tool Transfer

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling; T1573 Encrypted Channel

persistence

T1136 Create Account; T1505 Server Software Component; T1547 Boot or Logon Autostart Execution

initial-access

T1190 Exploit Public-Facing Application; T1566 Phishing

impact

T1486 Data Encrypted for Impact

resource-development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1591 Gather Victim Org Information; T1592 Gather Victim Host Information; T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in APT35 (Charming Kitten) GCC Pre-Positioning Cyber

  • ConnectWise — ScreenConnect
    Vulnerable versions: All versions before 23.9.8
    Fixed in: 23.9.8+
  • Ivanti — Connect Secure
    Vulnerable versions: 9.x, 22.x before patch
    Fixed in: Patched versions per advisory
  • Progress Software — Telerik UI for ASP.NET AJAX
    Vulnerable versions: Multiple versions
    Fixed in: Patched versions
  • PHP Group — PHP-CGI
    Vulnerable versions: 5.3.x and earlier
    Fixed in: 5.4+
  • Atlassian — Confluence Server
    Vulnerable versions: Multiple versions
    Fixed in: Patched per CVE-2023-22527
  • GitLab — GitLab CE/EE
    Vulnerable versions: Multiple versions
    Fixed in: Patched per CVE-2023-7028
  • Jenkins — Jenkins
    Vulnerable versions: Before 2.442, LTS before 2.426.3
    Fixed in: 2.442+, LTS 2.426.3+
  • Oracle — WebLogic Server
    Vulnerable versions: 10.3.6.0, 12.1.3.0, 12.2.1.1, 12.2.1.2
    Fixed in: Patched per CVE-2017-3506

Remediation for APT35 (Charming Kitten) GCC Pre-Positioning Cyber

Patches

  • Apply ConnectWise ScreenConnect patches for CVE-2024-1708 and CVE-2024-1709
  • Apply Ivanti Connect Secure patches for CVE-2024-21893 and CVE-2024-21887
  • Apply Telerik UI patches for CVE-2019-18935 and CVE-2017-11317
  • Apply Atlassian Confluence patches for CVE-2023-22527
  • Apply GitLab patches for CVE-2023-7028 and CVE-2021-22205
  • Apply Jenkins patches for CVE-2024-23897
  • Upgrade all PHP installations to mitigate CVE-2012-1823

Immediate actions

  • Block known APT35 C2 IP addresses at perimeter firewalls (185.141.63.55 and associated infrastructure)
  • Hunt for web shells across internet-facing servers, especially in IIS/ASP.NET and PHP environments
  • Review VPN and remote access logs for anomalous connections from Iranian IP ranges
  • Enable enhanced monitoring on all ConnectWise ScreenConnect and Ivanti Connect Secure instances
  • Audit domain admin accounts and service accounts for unauthorized additions
  • Block known APT35 domains (sunrapid.com, lydston.com, aecars.store) at DNS and proxy layers

Workarounds

  • Restrict external access to management interfaces for ConnectWise, Ivanti, and Telerik products
  • Implement geoblocking for connections originating from Iranian IP space where operationally feasible
  • Disable unnecessary remote access services and limit VPN access to required personnel only
  • Enable audit logging on all domain controllers and critical servers

Longer-term hardening

  • Deploy EDR with behavioral detection focused on PowerShell-based backdoors and lateral movement
  • Implement network segmentation between IT and OT/SCADA environments
  • Deploy SIEM rules for APT35 TTPs including web shell deployment, credential dumping, and large-volume data exfiltration
  • Establish threat hunting cadence focused on Iranian APT indicators
  • Implement phishing-resistant MFA across all remote access and privileged accounts
  • Conduct tabletop exercises simulating hybrid cyber-kinetic attack scenarios

CVEs associated with APT35 (Charming Kitten) GCC Pre-Positioning Cyber

CVE-2024-1708, CVE-2024-1709, CVE-2024-21893, CVE-2024-21887, CVE-2019-18935, CVE-2017-11317, CVE-2012-1823, CVE-2023-22527, CVE-2023-7028, CVE-2021-22205, CVE-2024-23897, CVE-2017-3506

Weaknesses (CWE) in APT35 (Charming Kitten) GCC Pre-Positioning Cyber

CWE-287, CWE-918, CWE-502, CWE-434, CWE-78, CWE-89, CWE-22, CWE-269

Timeline of APT35 (Charming Kitten) GCC Pre-Positioning Cyber

  • APT35/Charming Kitten first identified as an active Iranian state-sponsored threat group affiliated with IRGC-IO
  • Operation Afghan Infiltration begins — APT35 targets Afghan telecommunications systems and government ministries, exfiltrating 6,911 emails
  • Operation Shattered Mirror launched targeting Israel with mass surveillance via compromised routers and commercial website credential harvesting
  • APT35 achieves day-1 exploitation of ConnectWise ScreenConnect vulnerabilities (CVE-2024-1708/CVE-2024-1709), launching Operation Swiftstrike across Turkey, Saudi Arabia, Jordan, and UAE
  • Operation Desert Breach escalates with compromise of Jordanian Ministry of Justice, academic institutions, and law firms; 74 GB exfiltrated from single legal target
  • APT35 exploits Ivanti Connect Secure vulnerabilities (CVE-2024-21893/CVE-2024-21887) for VPN infrastructure compromise across GCC targets
  • APT35 pre-positioning across GCC critical infrastructure networks intensifies — persistent access established in UAE, Saudi Arabia, Qatar, Kuwait, and Bahrain
  • CloudSEK TRIAD team discovers and analyzes leaked APT35 internal operational documents on GitHub, exposing 17-member team structure, C2 infrastructure, and operational playbooks
  • Operation Epic Fury launched by US/Israel targeting Iranian nuclear infrastructure, IRGC compounds across 24 provinces; triggers Iranian kinetic retaliation using APT35-gathered targeting data
  • Iran launches multi-day ballistic missile and Shahed drone campaign against 7 nations (Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, Israel), enabled by APT35 cyber pre-positioning intelligence
  • Iranian APT groups including APT35, MuddyWater, APT33, APT34, and 60+ hacktivist proxies activate coordinated cyber campaign targeting GCC, Israel, and US infrastructure
  • CISA publishes advisory AA26-097A warning of Iranian-affiliated actors exploiting PLCs across US critical infrastructure sectors including water, energy, and government
  • CloudSEK publishes 'Kitten Had the Map All Along' report documenting APT35's GCC pre-positioning campaign and its direct link to kinetic military targeting
  • As of 2026-05-29, APT35/Charming Kitten remains an active, undeterred IRGC threat: its Nimbus Manticore subgroup is reported continuing operations after the Feb-May Operation Epic Fury campaign, and CISA advisory AA26-097A (Apr 7) still warns of ongoing Iranian APT critical-infrastructure exploitation. The shaky ceasefire has not halted cyber activity; no takedown or arrests reported.

Sources cited for APT35 (Charming Kitten) GCC Pre-Positioning Cyber

Threats related to APT35 (Charming Kitten) GCC Pre-Positioning Cyber

Detection coverage for TL-2026-0339

As of 2026-04-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0339 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats