logo

Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets

ID: b590401c-590f-5a5b-9d17-6df7971cd393

STIX ID: report--b590401c-590f-5a5b-9d17-6df7971cd393

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-02-22

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Charming Kitten (aka CharmingCypress/APT42), an Iran-linked nation-state actor, is conducting persistent, targeted social-engineering campaigns against Middle East policy experts worldwide using typo-squatted domains and a fake webinar platform; victims are lured to install Trojanized VPNs and other payloads that deploy backdoors (PowerLess on Windows, NokNok on macOS, Basicstar via LNK exploit), with the report detailing their patient rapport-building tradecraft and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.