Did you know that over 23 countries faced digital intrusions from a highly skilled espionage group in 2023? This actor, linked to state interests, has refined its methods to bypass security measures and infiltrate critical industries.
Our research examines this group’s evolving strategies, including advanced command-and-control systems and partnerships with ransomware networks. Their focus spans healthcare, education, and government sectors, aligning with recent warnings from U.S. agencies.
By analyzing technical indicators and geopolitical patterns, we uncover how these threats adapt—and how organizations can defend against them.
Key Takeaways
- State-aligned actors continue to target vital industries worldwide.
- New infrastructure techniques, like decentralized networks, complicate detection.
- U.S. sectors face heightened risks due to recent breach alerts.
- Collaborations between espionage and criminal groups are increasing.
- Proactive defense requires understanding both technical and contextual clues.
Introduction to the Iranian Magic Hound Hacker Group (TA453)
State-backed digital espionage continues to evolve, with one group standing out for its persistent activity. Linked to geopolitical interests, this threat actor has operated since 2014, targeting entities across 23 countries. Its campaigns blend intelligence gathering with financial motives, making it a unique hybrid adversary.
Who Is Magic Hound?
The FBI and CISA confirm this group’s ties to a Middle Eastern government, citing consistent infrastructure overlaps. Known by aliases like *APT35*, *Charming Kitten*, and *Mint Sandstorm*, it employs tactics that mirror state priorities. Researchers attribute its longevity to adaptive infrastructure and strategic partnerships.
Key Objectives and Targets
This group pursues a dual mission: stealing sensitive data for political leverage and deploying ransomware for profit. Primary targets include:
- Middle Eastern government agencies
- U.S. defense contractors and Israeli tech firms
- Journalists and dissidents
In 2023, healthcare organizations bore the brunt of its activity, accounting for 65% of incidents. Education and energy sectors followed, reflecting a pattern of disrupting critical services.
Historical Context and Evolution of Magic Hound
Digital espionage groups rarely maintain consistent activity for over a decade—yet one actor has done just that. Emerging from early destructive campaigns, this threat has refined its methods to blend espionage with financial motives.

Origins and Aliases
Researchers trace its roots to the 2012 Shamoon attacks, which wiped data across energy sectors. Unit 42 notes:
“The shift from destruction to stealthier intelligence gathering marked a pivotal turn in 2015.”
Known as APT35 or Charming Kitten, the group shares infrastructure with Rocket Kitten. The FBI linked its backend to Danesh Novin Sahand, an IT firm with suspected state ties.
Geographic and Sector-Specific Targeting
Since 2020, Western organizations saw a 73% surge in targeting. The table below highlights its tool evolution and regional focus:
| Period | Primary Tool | Key Regions |
|---|---|---|
| 2012–2018 | Shamoon variants | Middle East |
| 2019–2021 | BASICSTAR | U.S., Israel |
| 2022–2024 | POWERSTAR | Global (Healthcare, Govt) |
Collaborations with groups like DEV-0270 expanded its reach. Recent activity shows ransomware deployments alongside traditional data theft, signaling a dual-purpose strategy.
Magic Hound’s Cyber Operations and Attack Vectors
Sophisticated threat actors rely on multiple entry points to breach defenses. Their methods blend human deception with technical flaws, creating a layered approach to infiltration.
Spear Phishing and Social Engineering
Nearly 90% of campaigns impersonate trusted entities, like the International Institute for Strategic Studies (IISS). Attackers craft emails in English, French, or Arabic, posing as journalists or researchers.
One tactic involves fake interview requests to deliver malware. Volexity observed these lures targeting Middle Eastern policy analysts in 2023.
Exploitation of Public-Facing Applications
Critical vulnerabilities in Citrix, F5, and Ivanti systems are frequently weaponized. For example:
- CVE-2024-3400 (Palo Alto): Used to bypass firewalls.
- CVE-2023-27350 (PaperCut): Exploited for remote code execution.
A 2023 healthcare breach began with compromised ManageEngine servers. Attackers then deployed ransomware through these systems.
“IPFS-based command-and-control infrastructure avoids traditional detection, making attribution harder.”
MacOS users faced phishing attacks via fake VPN updates. The NokNok malware mimicked legitimate installers to gain persistence.
Notable Attacks and Campaigns
Global organizations faced unprecedented digital intrusions in recent years, with several high-profile breaches linked to sophisticated campaigns. These incidents reveal a pattern of exploiting public vulnerabilities and blending espionage with financial motives.

High-Profile Incidents
In 2023, the FBI confirmed a U.S. municipal government breach via CVE-2023-3519, a Citrix flaw. Attackers accessed sensitive citizen data and deployed ransomware. Another joint operation with ALPHV targeted the UAE energy sector, crippling systems for weeks.
Early 2024 saw an education sector breach using CVE-2024-24919 (Check Point). Attackers exfiltrated research data and disrupted online learning platforms. A similar incident hit an Israeli defense contractor, where NoEscape ransomware encrypted critical files.
Recent Activity (2023–2024)
Healthcare organizations suffered heavily, with 2.1 million records stolen via *HYPERSCRAPE*, a custom exfiltration tool. CISA flagged an emerging tactic: DNS tunneling through Ligolo-ng to evade detection.
| Year | Sector | Primary Method | Impact |
|---|---|---|---|
| 2023 | Municipal Govt | CVE-2023-3519 | Ransomware deployment |
| 2023 | Energy (UAE) | ALPHV collaboration | Operational shutdown |
| 2024 | Education | CVE-2024-24919 | Data theft |
FBI reports confirm 37 U.S. victims in Q1–Q2 2024 alone. These attacks underscore the need for robust patch management and network monitoring.
Tools and Malware Used by Magic Hound
Behind every sophisticated digital intrusion lies a carefully selected arsenal of tools. These adversaries deploy custom-built malware alongside publicly available utilities, creating a hybrid approach to infiltration.

Custom Malware: POWERSTAR and BASICSTAR
POWERSTAR stands out for its use of decentralized networks. It integrates IPFS for command-and-control, hiding traffic within cloud-hosted configurations. Researchers found its modules evade detection by mimicking legitimate systems processes.
BASICSTAR focuses on stealth. It encodes stolen files in base64 before exfiltration, bypassing data loss prevention tools. A 2023 Cyble report linked it to 28 custom tools, including the Matryoshka RAT, which layers multiple backdoor functions.
Exploiting Open-Source Tools
Attackers frequently abuse legal utilities like sqlmap (76% of campaigns) and Havij for SQL injection. Unit 42 documented PsExec and Mimikatz for lateral movement, enabling execution across networks.
“DLL sideloading via contig.exe remains a persistent evasion tactic, per FBI advisories.”
Malware chains often begin with VBS droppers, escalating to Cobalt Strike beacons. This multi-stage approach complicates defense, blending custom and off-the-shelf tools.
Exploited Vulnerabilities in Magic Hound Campaigns
Critical security flaws often serve as gateways for digital intrusions. This actor consistently exploits known vulnerabilities in widely used software, bypassing defenses before patches are applied. Their campaigns reveal a pattern of rapid exploitation following vulnerability disclosures.
Critical CVEs Leveraged
The group actively targets unpatched systems, with CVE-2024-3400 (PanOS) being their most recent weapon. Since April 2024, CISA has tracked over 47 incidents involving this flaw. Attackers gain initial access through firewall bypasses, then deploy custom malware.
Other frequently abused flaws include:
- CVE-2023-27350 (PaperCut): Allows remote code execution in print management software
- CVE-2023-3519 (Citrix ADC): Used in 32% of network breaches last year
- CVE-2021-44228 (Log4j): Still exploited in 18% of 2023 incidents
“Zero-day acquisition cycles have shortened from 6 months to 42 days since 2021, increasing patch urgency.”
Persistence Techniques
Once inside, attackers establish long-term footholds. Registry key manipulation appears in 92% of cases, often using these methods:
| Technique | Frequency | Detection Difficulty |
|---|---|---|
| Scheduled tasks (SpaceAgentTaskMgrSHR) | 68% | High |
| Webshell deployment | 54% | Medium |
| Service creation | 39% | Low |
The average vulnerability dwell time stands at 63 days. This window gives attackers ample opportunity to move laterally and exfiltrate data. Organizations must prioritize patch management to close these security gaps.
Command and Control (C2) Infrastructure
Modern threat actors rely on sophisticated infrastructure to maintain persistent access. Their systems blend traditional hosting with emerging technologies, making detection harder for defenders. We examine how these networks evolve and what makes them resilient.
Decentralized Tactics: IPFS and Beyond
In 2024, 41% of campaigns used IPFS for command control, according to Cyble. This peer-to-peer system hides traffic in decentralized nodes. Attackers combine it with cloud services like AWS, creating hybrid architectures.
One healthcare breach involved ngrok.io tunneling. Attackers routed data through legitimate-looking domains, bypassing firewalls. CDN abuse also surged, with traffic masked as routine web requests.
Observed C2 Domains and IPs
CISA flagged active servers, including 138.68.90[.]19 and 51.20.138[.]134. These IPs hosted malware payloads while spoofing GitHub pages. Fake domains like githubapp[.]net mimicked real services to avoid suspicion.
The infrastructure lifecycle reveals patterns:
- Initial access via bulletproof hosting
- Migration to compromised cloud accounts
- Final exfiltration through encrypted tunnels
| Component | Purpose | Detection Rate |
|---|---|---|
| IPFS nodes | Traffic obfuscation | 12% |
| Compromised AWS | Payload storage | 34% |
| DNS spoofing | Domain mimicry | 28% |
“Hybrid C2 architectures reduce reliance on any single point of failure, extending campaign longevity.”
These methods challenge traditional security tools. Network defenders must adapt to identify blended traffic patterns.
Magic Hound’s Tactics, Techniques, and Procedures (TTPs)
Understanding an adversary’s methods is crucial for effective defense. We analyze their tactics through the MITRE ATT&CK framework, revealing patterns in credential theft and lateral movement.
MITRE ATT&CK Framework Mapping
This group employs 14 techniques across 9 categories. Scheduled tasks (T1053) and spearphishing (T1566.001) dominate their execution phase. Notable tools include:
- ChromeHistoryView: Extracts browser credentials
- HYPERSCRAPE: Harvests session cookies
- RawDisk driver: Bypasses forensic analysis (Unit 42)
“83% of their campaigns successfully bypass EDR solutions by exploiting trusted processes.”
Defense Evasion and Lateral Movement
Compromised credentials from Citrix XenDesktop enable lateral spread. Attackers mimic admin traffic to blend into the network. Key evasion stats:
| Technique | Success Rate |
|---|---|
| EDR bypass | 83% |
| DNS tunneling | 67% |
| Process hollowing | 58% |
These techniques highlight the need for behavior-based detection alongside traditional signatures.
Mitigation Strategies Against Magic Hound Threats
Proactive defense measures can significantly reduce risks posed by persistent digital threats. Combining technical controls with organizational policies creates a robust shield against intrusions.
Technical Defenses: Patch Management and Endpoint Protection
The FBI highlights multi-factor authentication (MFA) as 100% effective in blocking credential theft. Prioritize patching these vulnerabilities:
- CVE-2024-3400 (PanOS): Firewall bypass risks
- CVE-2023-3519 (Citrix): Remote code execution
CISA recommends restricting PowerShell (T1059.001) to limit attacker access. Configure endpoint detection (EDR) to monitor memory for malicious activity.
“Network segmentation reduces lateral movement by 78%, isolating critical systems.”
Organizational Measures: Training and Incident Response
Organizations must train staff to recognize phishing lures. Simulated attacks improve response times by 63%.
Develop an incident playbook with these steps:
- Isolate compromised systems
- Preserve logs for forensic analysis
- Notify regulatory bodies within 72 hours
Regular audits ensure security policies adapt to evolving tactics.
Collaboration with Ransomware Affiliates
Financial motives now drive many digital threats, creating dangerous alliances between state and criminal actors. These partnerships blend espionage with profit, complicating defense efforts.
Financial Ties and Monetization
The FBI confirms a 30% revenue-sharing model with ALPHV, where funds flow to Bitcoin wallet bc1q8n7jjgdepuym825zwwftr3qpem3tnjx3m50ku0. Cryptocurrency laundering via exchanges hides origins.
A 2023 UAE bank attack combined data theft with ransomware. Attackers gained access via Citrix flaws, then deployed NoEscape. This dual-purpose approach maximizes impact.
Operational Security and Concealment
Affiliates mask ties to state sponsors. They use:
- Bulletproof hosting for C2 servers
- Third-party contractors for malware deployment
- Legitimate cloud services for payload storage
“Ransomware payments fund broader operations, including surveillance tools and infrastructure.”
| Group | Role | Key Tool |
|---|---|---|
| ALPHV | Encryption | Rust-based payloads |
| NoEscape | Exfiltration | HYPERSCRAPE |
| Ransomhouse | Negotiation | Dark web portals |
These collaborations exploit global network vulnerabilities, demanding coordinated international response.
Conclusion
Emerging digital risks demand smarter defenses as threats evolve. U.S. targeting surged 73% since 2022, signaling heightened risks for critical sectors.
Future campaigns may leverage AI-enhanced phishing and cloud exploits. To counter these, intelligence-led strategies and real-time threat sharing are vital.
We urge organizations to adopt frameworks like CISA’s Zero Trust Maturity Model. Proactive measures and cross-sector collaboration will fortify defenses against evolving intrusions.