Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets
ID: b590401c-590f-5a5b-9d17-6df7971cd393
STIX ID: report--b590401c-590f-5a5b-9d17-6df7971cd393
Feed Name: Dark Reading
Charming Kitten (aka CharmingCypress/APT42), an Iran-linked nation-state actor, is conducting persistent, targeted social-engineering campaigns against Middle East policy experts worldwide using typo-squatted domains and a fake webinar platform; victims are lured to install Trojanized VPNs and other payloads that deploy backdoors (PowerLess on Windows, NokNok on macOS, Basicstar via LNK exploit), with the report detailing their patient rapport-building tradecraft and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
