Files
APTs-Adversary-Simulation/Iranian APT/Charming Kitten
2026-04-27 09:39:27 -04:00
..
2026-04-27 09:39:27 -04:00

Charming Kitten APT Adversary Simulation

This is a simulation of attack by (Charming Kitten) APT group targeting multiple sectors government, military and critical infrastructure sectors across the Middle East. The groups targeting has expanded beyond government entities to encompass the maritime, aviation and financial sectors, reflecting a heightened interest in regional logistics and critical economic infrastructure. Recent campaigns have struck entities in Egypt, Saudi Arabia, the UAE , Turkey, Hungary, Turkmenistan, Israel and South America. These attacks demonstrate an ability to pivot between sectors while conducting multiple. The attack campaign was active in 2025 and early 2026. I relied on paloalto unit42 to figure out the details to make this simulation: https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/

Kitten

The initial campaign targeted project engineers using industry-specific terminology for subsea pipelines. The lure document was blurred in order to deceive targets into clicking “Enable Content,” thereby triggering the execution of the embedded macro.