Magic Hound
MITRE ATT&CK: G0059 View on attack.mitre.org
Aliases: TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm, Newscaster Team, Magic Hound, TunnelVision, COBALT MIRAGE, Agent Serpens, PHOSPHORUS, Parastoo
- First seen
- 2014-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 7
- Last IoC activity
- 2026-07-31 22:14:49
- Profile updated
- 2026-07-07 12:33:27
Targeted industries: government-and-public-sector media-and-entertainment education-and-nonprofits healthcare-and-pharmaceutical defense-and-aerospace
Targeted regions: country_code:us country_code:fr country_code:uk country_code:de country_code:ae country_code:sa
Context
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.
Detection coverage
- 10 YARA rules
- 990 Sigma rules
Malware & tools used
- Keylogging (attack-pattern)
- Exfiltration Over Web Service (attack-pattern)
- Credentials (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- PowerShell (attack-pattern)
- Wi-Fi Discovery (attack-pattern)
- Tool (attack-pattern)
- Domains (attack-pattern)
- Windows Command Shell (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Email Accounts (attack-pattern)
- Determine Physical Locations (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Web Protocols (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Email Accounts (attack-pattern)
- Scheduled Task (attack-pattern)
- Software (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Email Account (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Malicious File (attack-pattern)
- Rundll32 (attack-pattern)
Related threat objects
- APT42 (threat-actor)
- TA453 (threat-actor)
- DEV-0270 (threat-actor)
- OilRig (threat-actor)
- Cleaver (threat-actor)
- CHRYSENE (threat-actor)
- Clever Kitten (threat-actor)
- Rocket Kitten (threat-actor)
- Charming Kitten (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- Microsoft — New Steps To Protect Customers From Hacking (report)
- researchcenter.paloaltonetworks.com — Unit42 Magic Hound Campaign Attacks Saudi Targets (report)
- Mandiant — Mtrends 2018 (report)
- Microsoft — Evolving Trends In Iranian Threat Actor Activity Mstic Presentation At Cyberwarcon 2021 (report)
- MITRE ATT&CK — G0059 (report)
- cfr.org — Magic Hound (report)
- Palo Alto Unit 42 — Unit42 Magic Hound Campaign Attacks Saudi Targets (report)
- securityaffairs.co — Magic Hound Campaign (report)
- cfr.org — Apt 35 (report)
- research.checkpoint.com — Apt35 Exploits Log4J Vulnerability To Distribute New Modular Powershell Toolkit (report)
- sentinelone.com — Log4J2 In The Wild Iranian Aligned Threat Actor Tunnelvision Actively Exploiting Vmware Horizon (report)
- secureworks.com — Cobalt Mirage Conducts Ransomware Operations In Us (report)
- Palo Alto Unit 42 — Iranian Attackers Impersonate Model Agency (report)
- Microsoft — Defending Against Evolving Identity Attack Techniques (report)
- Microsoft — New Ttps Observed In Mint Sandstorm Campaign Targeting High Profile Individuals At Universities And Research Orgs (report)
- Microsoft — Nation State Threat Actor Mint Sandstorm Refines Tradecraft To Attack High Value Targets (report)
- Microsoft — Profiling Dev 0270 Phosphorus Ransomware Operations (report)
- proofpoint.com — Badblood Ta453 Targets Us And Israeli Medical Research Personnel Credential (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- clearskysec.com — Charming Kitten 2017 (report)
- blog.certfa.com — Charming Kitten Christmas Gift (report)
- Microsoft — Cyberattacks Phosphorus T20 Munich Security Conference (report)
- noticeofpleadings.com — Complaint (report)
External references
- mitre-attack — G0059
- Charming Kitten
- APT35
- ITG18
- Phosphorus
- Mint Sandstorm
- TA453
- COBALT ILLUSION
- Magic Hound
- Microsoft Phosphorus Mar 2019
- Microsoft Phosphorus Oct 2020
- Certfa Charming Kitten January 2021
- Check Point APT35 CharmPower January 2022
- ClearSky Charming Kitten Dec 2017
- ClearSky Kittens Back 2 Oct 2019
- ClearSky Kittens Back 3 August 2020
- Eweek Newscaster and Charming Kitten May 2014
- Unit 42 Magic Hound Feb 2017
- Newscaster
- FireEye APT35 2018