Files
APTs-Adversary-Simulation/Iranian APT/Charming Kitten/README.md
T
2026-04-27 09:39:27 -04:00

8 lines
1.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Charming Kitten APT Adversary Simulation
This is a simulation of attack by (Charming Kitten) APT group targeting multiple sectors government, military and critical infrastructure sectors across the Middle East. The groups targeting has expanded beyond government entities to encompass the maritime, aviation and financial sectors, reflecting a heightened interest in regional logistics and critical economic infrastructure. Recent campaigns have struck entities in Egypt, Saudi Arabia, the UAE , Turkey, Hungary, Turkmenistan, Israel and South America. These attacks demonstrate an ability to pivot between sectors while conducting multiple. The attack campaign was active in 2025 and early 2026. I relied on paloalto unit42 to figure out the details to make this simulation: https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/
<img width="679" height="381" alt="Kitten" src="https://github.com/user-attachments/assets/5056d989-0c3d-42c5-a4dd-529664ac7057" />
The initial campaign targeted project engineers using industry-specific terminology for subsea pipelines. The lure document was blurred in order to deceive targets into clicking “Enable Content,” thereby triggering the execution of the embedded macro.