logo

Charming Kitten Leak Exposes Key Personnel, Front Companies, and Thousands of Compromised Systems

ID: 826e699e-c9eb-5e87-b384-f2406be692b5

STIX ID: report--826e699e-c9eb-5e87-b384-f2406be692b5

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Charming Kitten (APT35) internal leaks reveal named operators, front companies and payrolls, and technical evidence tying the group to long‑running intrusion campaigns that compromise VPN gateways, email servers and endpoint systems across governments, universities and telecoms; infection is achieved via spear‑phishing and malicious documents that load PowerShell-based payloads which persist as scheduled tasks and beacon to Iranian-controlled HTTPS servers for command-and-control and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.