IranWidely attributedActiveMITRE G0058

Charming Kitten

Iran-attributed threat group conducting phishing and social engineering campaigns targeting academics, journalists, human rights activists, and policy experts. Particularly focused on individuals with knowledge of Iran.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
1.6
Low signal strength
Mentions2
Sources2
High conf.2
Last seenMay 2026
First observed
2014
Last active
Active
Origin
Iran — attributed by multiple Western vendors and governments to IRGC
Aliases
8
Techniques
0
Campaigns
0
Iran — attributed by multiple Western vendors and governments to IRGChigh confidence
TargetsAcademicJournalistNGOActivistGovernment
RegionsUsEuMiddle EastIl

Attribution signals

2 mentions · 2 sources
#1usehigh
Unspecified
eset
May 2026

"Russia-based SEABORGIUM and Iran-aligned TA453 groups use OSINT for reconnaissance ahead of spearphishing attacks on pre-selected targets."

#2observedhigh
Victimology
proofpoint
May 2026

"Proofpoint observed the Iran-aligned threat actor TA453 (Charming Kitten, Mint Sandstorm, APT42) conduct a credential phishing attempt against a US thinktank target."

Hedge terms observed

observeduse