Files
APTs-Adversary-Simulation/Iranian APT/Charming Kitten/README.md
T
2026-05-03 05:19:17 -04:00

11 lines
1.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Charming Kitten APT Adversary Simulation
This is a simulation of an attack by the APT group Charming Kitten, targeting government, military, and critical infrastructure sectors across the Middle East. The group has expanded its operations to include maritime, aviation, and financial sectors, showing increased interest in regional logistics and economic infrastructure.
Recent campaigns have impacted organizations in Egypt, Saudi Arabia, the UAE, Turkey, Hungary, Turkmenistan, Israel, and parts of South America. These attacks demonstrate the groups ability to pivot across multiple sectors while running concurrent operations. This simulation is based on research from Palo Alto Unit 42: https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/
<img width="679" height="381" alt="Kitten" src="https://github.com/user-attachments/assets/5056d989-0c3d-42c5-a4dd-529664ac7057" />
The initial campaign targeted project engineers using industry-specific terminology for subsea pipelines. The lure document was blurred in order to deceive targets into clicking “Enable Content,” thereby triggering the execution of the embedded macro.