216.73.217.22

APT35 Internal Leak of Hacking Campaigns Against Lebanon, Kuwait, Turkey, Saudi Arabia, Korea, and Domestic Iranian Targets

· Published 22/11/2025 13:38 · Modified 24/11/2025 09:46

Export JSON

Essential information

Published
22/11/2025 13:38
Modified
24/11/2025 09:46
Tags
2025-11-22 cyberespionage exchange herv phishing kit intelligence collection iran irgc middle east phishing powershort proxyshell rat-2ac2
Related entities
1 observables, 1 intrusion sets (apt), 5 techniques (mitre), 3 malware, 9 others

Description

An internal leak from APT35 (Charming Kitten) reveals a sophisticated, state-directed cyber-intelligence operation targeting diplomatic, government, and corporate networks in the and Asia. The documents expose a bureaucratic structure with defined workflows, performance metrics, and specialized teams for exploit development, credential theft, and campaigns. The group's focus on servers, use of exploits, and persistent mailbox monitoring demonstrate a strategic emphasis on long-term . The leak provides unprecedented insight into 's cyber capabilities, showing a mature apparatus that blends technical prowess with military-style oversight.

External references