Magic Hound, APT 35, Cobalt Illusion, Charming Kitten

Description

Magic Hound is an Iranian-sponsored threat group operating primarily in the Middle East that dates back as early as 2014. The group behind the campaign has primarily targeted organizations in the energy, government, and technology sectors that are either based or have business interests in Saudi Arabia.

Magic Hound has 2 subgroups:

  1. Subgroup: DEV-0270, Nemesis Kitten
  2. Subgroup: TA455, Smoke Sandstorm

This group appears to be the evolvement of Cutting Kitten, TG-2889.

There is some infrastructure overlap with Rocket Kitten, Newscaster, NewsBeef, ITG18 and APT 42.

Names

NameName-Giver
Magic HoundPalo Alto
APT 35Mandiant
Cobalt IllusionSecureWorks
Cobalt MirageSecureWorks
Charming KittenCrowdStrike
TEMP.BeanieFireEye
TimberwormSymantec
Tarh AndishanCylance
TA453Proofpoint
PhosphorusMicrosoft
TunnelVisionSentinelOne
UNC788FireEye
Yellow GarudaPWC
Educated ManticoreCheck Point
Mint SandstormMicrosoft
Ballistic BobcatESET
CharmingCypressVolexity
Agent SerpensPalo Alto

Country

State-sponsored, Islamic Revolutionary Guard Corps (IRGC)

Motivation

  • Information theft and espionage

First Seen

2012

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

bb9b25ed-9ddc-4f65-bd01-ab8d6efc34ac

Last Card Change

2025-06-28