Files
APTs-Adversary-Simulation/Iranian APT/Charming Kitten
2026-05-03 05:19:17 -04:00
..
2026-05-03 05:19:17 -04:00

Charming Kitten APT Adversary Simulation

This is a simulation of an attack by the APT group Charming Kitten, targeting government, military, and critical infrastructure sectors across the Middle East. The group has expanded its operations to include maritime, aviation, and financial sectors, showing increased interest in regional logistics and economic infrastructure.

Recent campaigns have impacted organizations in Egypt, Saudi Arabia, the UAE, Turkey, Hungary, Turkmenistan, Israel, and parts of South America. These attacks demonstrate the groups ability to pivot across multiple sectors while running concurrent operations. This simulation is based on research from Palo Alto Unit 42: https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/

Kitten

The initial campaign targeted project engineers using industry-specific terminology for subsea pipelines. The lure document was blurred in order to deceive targets into clicking “Enable Content,” thereby triggering the execution of the embedded macro.