created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Magic Hound
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0059 |
| Aliases | TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm |
| Attribution | Iran |
| Class | state |
| Active since | — |
| ATT&CK entry created | 2018-01-16 |
| Techniques mapped | 91 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1003.001 |
LSASS Memory |
T1005 |
Data from Local System |
T1016 |
System Network Configuration Discovery |
T1016.001 |
Internet Connection Discovery |
T1016.002 |
Wi-Fi Discovery |
T1018 |
Remote System Discovery |
T1021.001 |
Remote Desktop Protocol |
T1027.010 |
Command Obfuscation |
T1027.013 |
Encrypted/Encoded File |
T1033 |
System Owner/User Discovery |
T1036.004 |
Masquerade Task or Service |
T1036.005 |
Match Legitimate Resource Name or Location |
(First 12 of 91 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — Iran-linked actor, same attribution class
- Apt28 — Iran-linked actor, same attribution class
- Apt29 — Iran-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0059 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.