Magic Hound

MITRE ATT&CK: G0059 View on attack.mitre.org

Aliases: TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm, Newscaster Team, Magic Hound, TunnelVision, COBALT MIRAGE, Agent Serpens, PHOSPHORUS, Parastoo

First seen
2014-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
7
Last IoC activity
2026-07-31 22:14:49
Profile updated
2026-07-07 12:33:27

Targeted industries: government-and-public-sector media-and-entertainment education-and-nonprofits healthcare-and-pharmaceutical defense-and-aerospace

Targeted regions: country_code:us country_code:fr country_code:uk country_code:de country_code:ae country_code:sa

Context

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.

Detection coverage

  • 10 YARA rules
  • 990 Sigma rules

Malware & tools used

  • Keylogging (attack-pattern)
  • Exfiltration Over Web Service (attack-pattern)
  • Credentials (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • PowerShell (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • Tool (attack-pattern)
  • Domains (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Email Accounts (attack-pattern)
  • Determine Physical Locations (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Email Accounts (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Software (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Email Account (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Malicious File (attack-pattern)
  • Rundll32 (attack-pattern)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • Microsoft — New Steps To Protect Customers From Hacking (report)
  • researchcenter.paloaltonetworks.com — Unit42 Magic Hound Campaign Attacks Saudi Targets (report)
  • Mandiant — Mtrends 2018 (report)
  • Microsoft — Evolving Trends In Iranian Threat Actor Activity Mstic Presentation At Cyberwarcon 2021 (report)
  • MITRE ATT&CK — G0059 (report)
  • cfr.org — Magic Hound (report)
  • Palo Alto Unit 42 — Unit42 Magic Hound Campaign Attacks Saudi Targets (report)
  • securityaffairs.co — Magic Hound Campaign (report)
  • cfr.org — Apt 35 (report)
  • research.checkpoint.com — Apt35 Exploits Log4J Vulnerability To Distribute New Modular Powershell Toolkit (report)
  • sentinelone.com — Log4J2 In The Wild Iranian Aligned Threat Actor Tunnelvision Actively Exploiting Vmware Horizon (report)
  • secureworks.com — Cobalt Mirage Conducts Ransomware Operations In Us (report)
  • Palo Alto Unit 42 — Iranian Attackers Impersonate Model Agency (report)
  • Microsoft — Defending Against Evolving Identity Attack Techniques (report)
  • Microsoft — New Ttps Observed In Mint Sandstorm Campaign Targeting High Profile Individuals At Universities And Research Orgs (report)
  • Microsoft — Nation State Threat Actor Mint Sandstorm Refines Tradecraft To Attack High Value Targets (report)
  • Microsoft — Profiling Dev 0270 Phosphorus Ransomware Operations (report)
  • proofpoint.com — Badblood Ta453 Targets Us And Israeli Medical Research Personnel Credential (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • clearskysec.com — Charming Kitten 2017 (report)
  • blog.certfa.com — Charming Kitten Christmas Gift (report)
  • Microsoft — Cyberattacks Phosphorus T20 Munich Security Conference (report)
  • noticeofpleadings.com — Complaint (report)

External references