logo

An Insider Look At The IRGC-linked APT35 Operations: Ep3 - Malware Arsenal & Tooling

ID: b954857a-0cec-5909-a308-fd1a898568c9

STIX ID: report--b954857a-0cec-5909-a308-fd1a898568c9

Feed Name: CloudSEK Blog

Threat Score
92/100

Date Published: 2025-10-14

Date Updated: 2026-04-27

...
...

**Executive Summary:** Episode 3 documents reveal APT35/Charming Kitten's end-to-end malware development and operations, including two RAT families (Saqeb System and RAT-2AC2), custom ASP webshells using an Accept-Language covert channel, QA/FUD testing practices, credential-stealing modules, VNC exfiltration tooling, and infrastructure leveraging TOR and multi-hop relays; the collection asserts 300+ compromised sites across multiple Middle Eastern countries and outlines targeting of aviation, law enforcement, SCADA/industrial systems and planned ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.