Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets – Dark Reading
Conflicts in the Middle East, Ukraine, and other areas of simmering geopolitical tensions have made policy experts the latest target of cyber operations conducted by state-sponsored groups.
An Iran-linked group known as Charming Kitten, CharmingCypress, and APT42 recently targeted Middle East policy experts in the region as well as in the US and Europe, using a phony webinar platform to compromise its targeted victims, incident response services firm Volexity stated in an advisory published this month.
Charming Kitten is well known for its extensive social engineering tactics, including low-and-slow social engineering attacks against think tanks and journalists to gather political intelligence, the firm stated.
The group often dupes is targets into installing Trojan-rigged VPN applications to gain access to the fake webinar platform and other sites, resulting in the installation of malware. Overall, the group has embraced the long confidence game, says Steven Adair, co-founder and president of Volexity.
"I don't know if that is necessarily sophisticated and advanced, but it is a lot of effort," he says. "It's more advanced and more sophisticated than your average attack by a significant margin. It's a level of effort and dedication ... that is definitely different and uncommon ... to go to that much effort for such a specific set of attacks."
Policy experts are a frequently targeted by nation-state groups. The Russia-linked ColdRiver group, for example, has targeted nongovernmental organizations, military officers, and other experts using social engineering to gain the confidence of the victim and then following up with a malicious link or malware. In Jordan, targeted exploitation reportedly by government agencies used the Pegasus spyware program developed by the NSO Group and targeted journalists, digital-rights lawyers, and other policy experts.
Other companies have also described Charming Kitten/CharmingCypress' tactics. In a January advisory, Microsoft warned that the group, which it calls Mint Sandstorm, had targeted journalists, researchers, professors, and other experts covering security and policy topics of interest to the Iranian government.
"Operators associated with this subgroup of Mint Sandstorm are patient and highly skilled social engineers whose tradecraft lacks many of the hallmarks that allow users to quickly identify phishing emails," Microsoft stated. "In some instances of this campaign, this subgroup also used legitimate but compromised accounts to send phishing lures."
The group has been active since at least 2013, has strong links to the Islamic Revolutionary Guard Corps (IRGC), and has not been directly involved in the cyber-operational aspect of the conflict between Israel and Hamas, according to cybersecurity firm CrowdStrike.
"Unlike in the Russia-Ukraine war, where known cyber operations have directly contributed to the conflict, those involved in the Israel-Hamas conflict have not directly contributed to Hamas military operations against Israel," the company stated in its "2024 Global Threat Report" released on Feb. 21.
These attacks usually start with spear-phishing and end with a combination of malware delivered to the target's system, according to an advisory from Volexity, which calls the group CharmingCypress. In September and October 2023, CharmingCypress used a number of typo-squatted domains addresses similar to legitimate domains to pose as officials from the International Institute of Iranian Studies (IIIS) to invite policy experts to a webinar. The initial email demonstrated the low-and-slow approach of CharmingCypress, eschewing any malicious link or attachment and inviting the targeted professional to reach out through other channels of communications, such as WhatsApp and Signal.
Using in-depth spearphishing, CharmingCypress aims to convince policy experts to install malware. Source: Volexity
The attacks target Middle East policy experts worldwide, with Volexity encountering a majority of attacks against European and US professionals, Adair says.
"They are quite aggressive," he says. "They'll even set up entire email chains or a phishing scenario where they're looking for comment and there's other people maybe three, four, or five people on that email thread with the exception of the target they're definitely trying to build rapport."
The long con eventually delivers a payload. Volexity identified five different malware families associated with the threat. The PowerLess backdoor is installed by the Windows version of the malware-laden virtual private network (VPN) application, which uses PowerShell to allow files to be transferred and executed, as well as targeting specific data on the system, logging keystrokes, and capturing screenshots. A macOS version of the malware is dubbed NokNok, while a separate malware chain using a RAR archive and LNK exploit leads to a backdoor named Basicstar.
The group's approach to social engineering definitely embodies the "persistence" piece of the advanced persistent threat (APT). Volexity sees a "constant barrage" of attacks, so policy experts have to become even more suspicious of cold contacts, Adair says.
Doing so will be difficult, as many policy experts are academics in constant contact with students or members of the public and are not used to being strict with their contacts, he says. Yet they should definitely think before opening documents or entering credentials into a site reached through an unknown link.
"At the end of the day, they have to get the person to click something or open something, which if I want you to review a paper or something like that, means ... being very wary of links and files," Adair says. "If I have to enter my credentials at any point in time, or authorize something that should be a major red flag. Similarly, if I'm being asked to download something, that should be a pretty big red flag."
In addition, policy experts need to understand that CharmingCypress will continue to target them even if its attempts fail, Volexity stated.
"This threat actor is highly committed to conducting surveillance on their targets in order to determine how best to manipulate them and deploy malware," the company stated in its advisory. "Additionally, few other threat actors have consistently churned out as many campaigns as CharmingCypress, dedicating human operators to support their ongoing efforts."
Originally posted here:
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets - Dark Reading
- U.S. and Iran hold first round of nuclear talks and agree to meet again next week - NPR - April 14th, 2025 [April 14th, 2025]
- Iran and U.S. agree to more talks over Tehrans nuclear program - NBC News - April 14th, 2025 [April 14th, 2025]
- U.S. and Iran see Saturday's nuclear talks as test of whether other side wants a deal - Axios - April 14th, 2025 [April 14th, 2025]
- Iran: Talks with US to stay indirect, will only address nuclear issues and sanctions - The Times of Israel - April 14th, 2025 [April 14th, 2025]
- Mideast mediator Oman at the center of a key first Iran-US meeting over Tehran's nuclear program - AP News - April 14th, 2025 [April 14th, 2025]
- Iran, US hold 'positive' talks in Oman, agree to resume next week - Reuters - April 14th, 2025 [April 14th, 2025]
- Iran and US envoys hold 1st negotiation over Tehran's nuclear program, and talk face-to-face - AP News - April 14th, 2025 [April 14th, 2025]
- Iranian Foreign Minister to Visit Moscow Ahead of Second Iran-US Meeting - Algemeiner.com - April 14th, 2025 [April 14th, 2025]
- Iran delegation holds 'indirect' nuclear talks with US in Oman, state media says - ABC News - April 14th, 2025 [April 14th, 2025]
- Trump: 'We will solve Iran problem' - The Jerusalem Post - April 14th, 2025 [April 14th, 2025]
- US-Iran negotiators hold constructive nuclear talks, will meet again next week - CNN - April 14th, 2025 [April 14th, 2025]
- As U.S. and Iran begin nuclear talks amid fresh sanctions, can there be a deal? - NBC News - April 14th, 2025 [April 14th, 2025]
- Iran Has a Reason to Strike a Nuclear Deal: Its Economy Is in Trouble - WSJ - April 14th, 2025 [April 14th, 2025]
- US signals openness to compromise in Iran talks: Red line is nuclear weaponization - The Times of Israel - April 14th, 2025 [April 14th, 2025]
- US and Iran hold 'constructive' first round of nuclear talks - BBC - April 14th, 2025 [April 14th, 2025]
- Envoys from Iran and the US arrive in Oman for first round of talks over Tehran's nuclear program - ABC News - April 14th, 2025 [April 14th, 2025]
- Iranian foreign minister will consult on Iran-U.S. talks during visit to Russia - Yahoo - April 14th, 2025 [April 14th, 2025]
- 7 years after pulling out, why is Donald Trump re-engaging Iran on nuclear deal, and what does Israel wan - Times of India - April 14th, 2025 [April 14th, 2025]
- Rep. McCormick praises Trump admin's nuclear talks with Iran: 'Great step in the right direction' - Fox News - April 14th, 2025 [April 14th, 2025]
- What is Iran's nuclear programme and what do the US and Israel want? - BBC - April 14th, 2025 [April 14th, 2025]
- China's oil imports highest since 2023 amid Iran crude spike: What to know - AL-Monitor - April 14th, 2025 [April 14th, 2025]
- Trump: Solving Issues With Iran Almost Easy Ahead of New Round of Talks - Algemeiner.com - April 14th, 2025 [April 14th, 2025]
- What to Know About U.S. Talks With Iran Over Its Nuclear Program - The New York Times - April 14th, 2025 [April 14th, 2025]
- STATEMENT FROM THE WHITE HOUSE - U.S. Virtual Embassy Iran (.gov) - April 14th, 2025 [April 14th, 2025]
- Exclusive | Witkoff Says U.S. Open to Compromise Ahead of Iran Nuclear Talks - WSJ - April 14th, 2025 [April 14th, 2025]
- Next Iran-US nuclear talks to be held in Rome, AP source says, as Italy prepares for negotiations - KTSA - April 14th, 2025 [April 14th, 2025]
- AP: Next Iran-US nuclear talks will be held in Rome - dailyadvance.com - April 14th, 2025 [April 14th, 2025]
- US army sends message to Iran - with quote from 'Harbu Darbu' - www.israelhayom.com - April 14th, 2025 [April 14th, 2025]
- Iran and the US: The price of a deal or the cost of war across West Asia? - thecradle.co - April 14th, 2025 [April 14th, 2025]
- An emboldened US and a weakened Iran will hold nuclear talks. Is there space for a deal? - CNN - April 14th, 2025 [April 14th, 2025]
- Khamenei aide: Iran will have no choice but to acquire nukes if attacked - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- How dangerous are the tensions between the US and Iran? - Al Jazeera - April 1st, 2025 [April 1st, 2025]
- Russia condemns Trumps threat to bomb Iran over nuclear standoff - Anadolu Ajans - April 1st, 2025 [April 1st, 2025]
- Iran threatens preemptive strike on base housing US bombers, report says - Ynetnews - April 1st, 2025 [April 1st, 2025]
- Exclusive: Iran has readied missiles for potential response amid Trump's escalating threats - Tehran Times - April 1st, 2025 [April 1st, 2025]
- Iran's Khamenei vows retaliation if Trump threat enacted - DW - April 1st, 2025 [April 1st, 2025]
- Iran has rejected direct negotiations with the US in response to Trumps letter - AP News - April 1st, 2025 [April 1st, 2025]
- US sanctions entities in Iran, China, UAE, for assisting Tehran with weapons procurement - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- Khamenei adviser says Iran will have no choice but to get nuclear weapon if attacked - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- A Ticking Bomb: Israeli Eliminates Iran-Linked Terrorist in Beirut - Foundation for Defense of Democracies - April 1st, 2025 [April 1st, 2025]
- 'Will have no choice': Iran warns it may have to acquire nuclear weapons if attacked - Times of India - April 1st, 2025 [April 1st, 2025]
- Trump threatens there will be bombing if Iran fails to make deal on nukes - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- Suspected missile cargo ship arrives in Iran from China as nuclear tensions escalate - Newsweek - April 1st, 2025 [April 1st, 2025]
- Trump threatens to bomb Iran if nuclear deal cant be reached - Politico - April 1st, 2025 [April 1st, 2025]
- Trump warns Iran could see 'bombing the likes of which they have never seen' - www.israelhayom.com - April 1st, 2025 [April 1st, 2025]
- Iran rejects direct nuclear talks with Trump, open to indirect negotiations - Al Jazeera - April 1st, 2025 [April 1st, 2025]
- Iran's Supreme Leader Responds to Trump Bombing Threat - Newsweek - April 1st, 2025 [April 1st, 2025]
- Is Iran on a collision course with the west? - Financial Times - April 1st, 2025 [April 1st, 2025]
- Trump says 'there will be bombing' if Iran does not make nuclear deal - USA Today - April 1st, 2025 [April 1st, 2025]
- Mapped: These are the nuclear sites in Iran the US and Israel could hit if talks fail - Ynetnews - April 1st, 2025 [April 1st, 2025]
- Trump warns Iran of bombing like never seen before if no deal reached - - April 1st, 2025 [April 1st, 2025]
- IDF reorganizes units responsible for Iran planning - The Times of Israel - April 1st, 2025 [April 1st, 2025]
- Trump threatens to bomb Iran unless deal on nuclear program is reached - The Independent - April 1st, 2025 [April 1st, 2025]
- Trump's threat to Iran that 'there will be bombing' comes amid new B-2 stealth bomber moves - Business Insider - April 1st, 2025 [April 1st, 2025]
- Israel and the United States are Ready to Strike Iran - The National Interest - April 1st, 2025 [April 1st, 2025]
- Two Carriers in the Middle East: Implications for the Houthis, Iran, and U.S. Force Readiness - The Washington Institute - April 1st, 2025 [April 1st, 2025]
- Iran Is Freaked: Trump and Israel Could Launch a Joint Strike - 19FortyFive - April 1st, 2025 [April 1st, 2025]
- Trump's threat to Iran that 'there will be bombing' comes amid new B-2 stealth bomber moves - MSN - April 1st, 2025 [April 1st, 2025]
- Iran rejects offer of direct US negotiations over rapidly growing nuclear program - New York Post - April 1st, 2025 [April 1st, 2025]
- Trump's threat to Iran that 'there will be bombing' comes amid new B-2 stealth bomber moves - Yahoo - April 1st, 2025 [April 1st, 2025]
- Trumps Middle East strategy is all about striking an Iran deal. Gaza could get in the way. - Atlantic Council - March 25th, 2025 [March 25th, 2025]
- US Threatens 'All Options on the Table' for Iran - Newsweek - March 25th, 2025 [March 25th, 2025]
- Trump's offer of talks with Iran aims to avoid military action, US envoy says - Reuters - March 25th, 2025 [March 25th, 2025]
- Trumps Advisers Are Divided on Iran. Which Way Is the President Leaning? - The FP - March 25th, 2025 [March 25th, 2025]
- Iranians discuss Trump envoys interest in visiting Tehran | Iran International - - March 25th, 2025 [March 25th, 2025]
- Iran's top medical body warns of skilled staff exodus - - March 25th, 2025 [March 25th, 2025]
- Iran says it will consider 'opportunities' as well as threats in Trump letter - Reuters - March 25th, 2025 [March 25th, 2025]
- Khamenei says Houthis act independently, warns against US strikes on Iran - The Times of Israel - March 25th, 2025 [March 25th, 2025]
- Iran condemns US threats to use force and vows to defend its sovereignty - The Times of Israel - March 25th, 2025 [March 25th, 2025]
- Iran's Khamenei says US threats 'will get them nowhere' - FRANCE 24 English - March 25th, 2025 [March 25th, 2025]
- Iran's Supreme Leader Threatens US with "Severe Blow" - Newsweek - March 25th, 2025 [March 25th, 2025]
- Iran's supreme leader says Trump administration threats over nuclear program "will get them nowhere" - CBS News - March 25th, 2025 [March 25th, 2025]
- Iran open to indirect talks with US, rejects direct negotiations under pressure - Arutz Sheva - March 25th, 2025 [March 25th, 2025]
- How a war with Iran (for Israel) could crash the US economy - The Cradle - March 25th, 2025 [March 25th, 2025]
- Iran has 'got to address that fact that the world they knew is over': State Department spox - Fox Business - March 25th, 2025 [March 25th, 2025]
- No one can even think of attack on Iran, FM asserts - Tehran Times - March 25th, 2025 [March 25th, 2025]
- The Islamic Republic of Iran only understands one language: 'Language of pressure,' journalist say - Fox Business - March 25th, 2025 [March 25th, 2025]
- French citizen Olivier Grondeau is freed after over 880 days in a prison in Iran - The Associated Press - March 25th, 2025 [March 25th, 2025]
- Iran's leader warns US could receive 'severe slaps' following Trump's threats to Houthis - Fox News - March 25th, 2025 [March 25th, 2025]
- US and Israel Have Laid the Groundwork for War With Iran. Will Trump Set It Off? - Truthout - March 25th, 2025 [March 25th, 2025]