Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.

Attribute Detail
ATT&CK ID G0059
Aliases TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm
Attribution Iran
Class state
Active since
ATT&CK entry created 2018-01-16
Techniques mapped 91

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1003.001 LSASS Memory
T1005 Data from Local System
T1016 System Network Configuration Discovery
T1016.001 Internet Connection Discovery
T1016.002 Wi-Fi Discovery
T1018 Remote System Discovery
T1021.001 Remote Desktop Protocol
T1027.010 Command Obfuscation
T1027.013 Encrypted/Encoded File
T1033 System Owner/User Discovery
T1036.004 Masquerade Task or Service
T1036.005 Match Legitimate Resource Name or Location

(First 12 of 91 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Ke3Chang — Iran-linked actor, same attribution class
  • Apt28 — Iran-linked actor, same attribution class
  • Apt29 — Iran-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0059 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.