FORENSIA

THREAT_ACTOR · G0059

Magic Hound

Also known as: Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm

Profile

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.

MITRE ATT&CK ↗

Techniques

78 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1005 Data from Local SystemT1016 System Network Configuration DiscoveryT1016.001 Internet Connection DiscoveryT1016.002 Wi-Fi DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1027.010 Command ObfuscationT1027.013 Encrypted/Encoded FileT1033 System Owner/User DiscoveryT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1036.010 Masquerade Account NameT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1056.001 KeyloggingT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1070.003 Clear Command HistoryT1070.004 File DeletionT1071 Application Layer ProtocolT1071.001 Web ProtocolsT1078.001 Default AccountsT1078.002 Domain AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.003 Email AccountT1090 ProxyT1098.002 Additional Email Delegate PermissionsT1098.007 Additional Local or Domain GroupsT1102.002 Bidirectional CommunicationT1105 Ingress Tool TransferT1112 Modify RegistryT1113 Screen CaptureT1114 Email CollectionT1114.001 Local Email CollectionT1114.002 Remote Email CollectionT1136.001 Local AccountT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1204.001 Malicious LinkT1204.002 Malicious FileT1218.011 Rundll32T1482 Domain Trust DiscoveryT1486 Data Encrypted for ImpactT1505.003 Web ShellT1547.001 Registry Run Keys / Startup FolderT1560.001 Archive via UtilityT1564.003 Hidden WindowT1566.002 Spearphishing LinkT1566.003 Spearphishing via ServiceT1567 Exfiltration Over Web ServiceT1570 Lateral Tool TransferT1571 Non-Standard PortT1572 Protocol TunnelingT1573 Encrypted ChannelT1583.001 DomainsT1583.006 Web ServicesT1584.001 DomainsT1585.001 Social Media AccountsT1585.002 Email AccountsT1586.002 Email AccountsT1588.002 ToolT1589 Gather Victim Identity InformationT1589.001 CredentialsT1589.002 Email AddressesT1590.005 IP AddressesT1591.001 Determine Physical LocationsT1592.002 SoftwareT1595.002 Vulnerability ScanningT1598.003 Spearphishing LinkT1685 Disable or Modify ToolsT1685.001 Disable or Modify Windows Event LogT1686.003 Windows Host Firewall

Software

13 malware/tools attributed to this actor.

MimikatzPsExecNetSysteminfoPingipconfignetshDownPaperPupyImpacketCharmPowerPowerLessFRP

Related corpus activity

10,449 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Magic Hound.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-2492cve852
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,449.