APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting — Threadlinqs Intelligence
As of 2026-05-30, APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting is a critical-severity apt threat attributed to APT35 (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0339 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: APT35 · Iran · ESPIONAGE
Iran-linked APT35 (Charming Kitten), an IRGC-affiliated threat group, conducted years of systematic cyber reconnaissance and pre-positioning across GCC nations including UAE, Saudi Arabia, Qatar,
APT35, also tracked as Charming Kitten, Phosphorus, Mint Sandstorm, TA453, Magic Hound, COBALT ILLUSION, and ITG18, is an Iranian state-sponsored cyber espionage group affiliated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). Active since at least 2011, the group has evolved from basic phishing operations into a sophisticated multi-division offensive cyber unit capable of long-term infrastructure compromise and intelligence preparation of the environment (IPE).
In a groundbreaking report published April 9, 2026, CloudSEK's TRIAD research team documented how APT35 systematically pre-positioned itself across critical infrastructure networks in Gulf Cooperation Council (GCC) nations over a multi-year campaign. This pre-positioning served a dual purpose: traditional espionage and — critically — the generation of targeting intelligence that directly supported Iran's kinetic military operations following Operation Epic Fury.
Operation Epic Fury, launched by the United States and Israel on February 28, 2026, struck Iranian nuclear infrastructure, ballistic missile production facilities, and IRGC compounds across 24 provinces. Iran responded with a multi-day ballistic missile and Shahed drone campaign targeting seven nations: Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, and Israel. CloudSEK's analysis reveals that APT35's pre-positioned access across these same nations provided critical targeting data — infrastructure maps, network topologies, and operational intelligence — that enabled precision targeting of critical facilities.
The campaign leveraged multiple attack vectors. APT35 exploited recently disclosed vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1708/CVE-2024-1709), Ivanti Connect Secure (CVE-2024-21893/CVE-2024-21887), Telerik UI (CVE-2019-18935/CVE-2017-11317), PHP-CGI (CVE-2012-1823), and other enterprise platforms, often achieving exploitation within 48 hours of CVE disclosure. Their toolset included custom malware such as the RTM Project RAT (a modular Remote Access Trojan with Active Directory integration), WezRAT infostealer, and commodity tools including Nuclei, RouterScan, SQLMap, and Acunetix.
A late 2025 leak of APT35's internal operational documents by CloudSEK revealed a 17-member operational structure organized into four divisions: Operations Command, Project Managers, Specialized Operators, and Generic Operators. The leak exposed C2 infrastructure, operational playbooks, and evidence of massive data exfiltration — including 74 GB from a single Jordanian legal target and 6,911 emails from Afghan government ministries. Despite this exposure, APT35 rapidly refreshed infrastructure and remained operational.
Confirmed sub-campaigns include Operation Shattered Mirror (Israel, mass surveillance via compromised routers), Operation Desert Breach (Jordan, government and legal sector compromise), and Operation Swiftstrike (multi-country ConnectWise/Ivanti exploitation targeting Turkey, Saudi Arabia, Jordan, and UAE). The group's activities across GCC nations constitute the most significant documented case of cyber operations directly enabling kinetic military targeting, representing a paradigm shift in hybrid warfare.
Weaknesses (CWE)
CWE-287, CWE-918, CWE-502, CWE-434, CWE-78, CWE-89, CWE-22, CWE-269
Target sectors: government, critical-infrastructure, defense, energy, water, education, legal, financial, telecommunications, aviation, healthcare
Target regions: Saudi Arabia, UAE, Kuwait, Bahrain, Qatar, Jordan, Israel, Turkey, Oman, Azerbaijan
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2024-1708, CVE-2024-1709, CVE-2024-21893, CVE-2024-21887, CVE-2019-18935, CVE-2017-11317, CVE-2012-1823, CVE-2023-22527, CVE-2023-7028, CVE-2021-22205, T1595, T1592, T1590, T1591, T1589, T1583, T1588, T1585, T1190, T1566