Charming Kitten APT Adversary Simulation
This is a simulation of an attack by the APT group Charming Kitten, targeting government, military, and critical infrastructure sectors across the Middle East. The group has expanded its operations to include maritime, aviation, and financial sectors, showing increased interest in regional logistics and economic infrastructure.
Recent campaigns have impacted organizations in Egypt, Saudi Arabia, the UAE, Turkey, Hungary, Turkmenistan, Israel, and parts of South America. These attacks demonstrate the group’s ability to pivot across multiple sectors while running concurrent operations. This simulation is based on research from Palo Alto Unit 42: https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/
The initial campaign targeted project engineers using industry-specific terminology for subsea pipelines. The lure document was blurred in order to deceive targets into clicking “Enable Content,” thereby triggering the execution of the embedded macro.