216.73.217.22

GreenCharlie Infrastructure Linked to US Political Campaign Targeting

· Published 21/08/2024 10:48 · Modified 21/08/2024 11:00

Export JSON

Essential information

Published
21/08/2024 10:48
Modified
21/08/2024 11:00
Tags
2024-08-21 apt espionage gorble iran malware phishing powerstar
Related entities
111 observables, 1 intrusion sets (apt), 12 techniques (mitre), 2 malware, 3 others

Description

An analysis by Insikt Group revealed a significant surge in cyber threat activities from GreenCharlie, an -linked group associated with Mint Sandstorm, Charming Kitten, and APT42. The group persistently targets US political and governmental entities through sophisticated operations involving like and . Their infrastructure employs dynamic DNS providers and deceptive domain themes to facilitate attacks. Recorded Future's Network Intelligence identified -based IP addresses communicating with GreenCharlie's infrastructure, further suggesting Iranian involvement in these operations.

External references