Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Magic Hound

🇮🇷Magic Hound

🇮🇷 Magic Hound is a tracked threat actor in the Clankerusecase corpus. IR-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 78 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.

View full actor card → All threat actors MITRE ATT&CK group spec (G0059) ↗
14Use cases
0Articles
78Techniques
0IOCs

About this actor (MITRE)

[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Securew

Known aliases

Magic HoundTA453COBALT ILLUSIONCharming KittenITG18PhosphorusNewscasterAPT35Mint Sandstorm

Top techniques

All other tracked techniques

T1016.001 · Internet Connection DiscoveryT1016.002 · Wi-Fi DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1027.010 · Command ObfuscationT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1036.010 · Masquerade Account NameT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.003 · Clear Command HistoryT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1078.001 · Default AccountsT1078.002 · Domain AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.003 · Email AccountT1090 · ProxyT1098.002 · Additional Email Delegate PermissionsT1098.007 · Additional Local or Domain GroupsT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1112 · Modify RegistryT1113 · Screen CaptureT1114 · Email CollectionT1114.001 · Local Email CollectionT1114.002 · Remote Email CollectionT1136.001 · Local AccountT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1204.001 · Malicious LinkT1204.002 · Malicious FileT1218.011 · Rundll32T1482 · Domain Trust DiscoveryT1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1547.001 · Registry Run Keys / Startup FolderT1560.001 · Archive via UtilityT1564.003 · Hidden WindowT1566.002 · Spearphishing LinkT1566.003 · Spearphishing via ServiceT1567 · Exfiltration Over Web ServiceT1570 · Lateral Tool TransferT1571 · Non-Standard PortT1572 · Protocol TunnelingT1573 · Encrypted ChannelT1583.001 · DomainsT1583.006 · Web ServicesT1584.001 · DomainsT1585.001 · Social Media AccountsT1585.002 · Email AccountsT1586.002 · Email AccountsT1588.002 · ToolT1589 · Gather Victim Identity InformationT1589.001 · CredentialsT1589.002 · Email AddressesT1590.005 · IP AddressesT1591.001 · Determine Physical LocationsT1592.002 · SoftwareT1595.002 · Vulnerability ScanningT1598.003 · Spearphishing LinkT1685 · Disable or Modify ToolsT1685.001 · Disable or Modify Windows Event LogT1686.003 · Windows Host Firewall

Detection use cases (14)

Magic Hound (APT35/Charming Kitten) CharmPower/PowerLess maldoc chain — Office-spawned scripting host followed by schtasks persistence AI · profile S Magic Hound (TA453/Charming Kitten) post-compromise mailbox-rule abuse — auto-forward / delete inbox rules with external recipient AI · profile S Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) MITRE match