Magic Hound
Also tracked as TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.
- Documented techniques
- 78
- Assessed origin
- Iran
- Assessed motivation
- Espionage
- First seen
- 2014
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance8
resource development7
initial access4
execution7
persistence5
credential access1
discovery12
- T1016 System Network Configuration Discovery
- T1016.001 Internet Connection Discovery
- T1016.002 Wi-Fi Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.003 Email Account
- T1482 Domain Trust Discovery
lateral movement2
collection7
command and control8
exfiltration1
defense impairment4
stealth11
- T1027.010 Command Obfuscation
- T1027.013 Encrypted/Encoded File
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1036.010 Masquerade Account Name
- T1070.003 Clear Command History
- T1070.004 File Deletion
- T1078.001 Default Accounts
- T1078.002 Domain Accounts
- T1218.011 Rundll32
- T1564.003 Hidden Window
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.