216.73.216.233

CHARMING KITTEN

· Published 04/10/2024 10:16 · Modified 04/10/2024 12:41

Export JSON

Essential information

Published
04/10/2024 10:16
Modified
04/10/2024 12:41
Tags
2024-10-04 apt42 credential phishing domain registration infrastructure iran mint sandstorm spear-phishing ta453
Related entities
11 observables, 1 intrusion sets (apt), 6 techniques (mitre), 7 others

Description

Since June 2024, the -nexus actor CHARMING KITTEN has been creating new network for , targeting individuals perceived as threats to the Iranian regime. The actor's , known as Cluster B, uses domains with specific characteristics like similar TLDs, hyphenated naming conventions, and shared IP addresses. While specific targets for the new domains are unknown, previous targets included researchers, journalists, NGO leaders, and human rights activists. The phishing pages often mimic login interfaces for popular services like Google and YouTube, distributed through emails disguised as conference invitations or links to legitimate documents.

External references