Charming Kitten (APT35)
A threat profile of Charming Kitten (APT35), an Iranian state-aligned cyber espionage group known for credential harvesting, social engineering, and targeting academics, NGOs, and policymakers worldwide.
SOC status:Duty analyst on shift
Insights
Research, detection engineering notes and plain-English explanations for the questions UK boards, IT managers and security leads actually ask. One substantial piece a week; a short threat brief in between.
Get the fortnightly briefing
A threat profile of Charming Kitten (APT35), an Iranian state-aligned cyber espionage group known for credential harvesting, social engineering, and targeting academics, NGOs, and policymakers worldwide.
A threat profile of BlackCat (ALPHV), a technically advanced ransomware group known for multi-extortion tactics, cross-platform payloads, and attacks on critical infrastructure across the UK and beyond.
A detailed threat profile of APT41, a China-based state-sponsored group known for blending cyber espionage with financially motivated attacks, targeting healthcare, telecoms, finance, and critical infrastructure globally.
A threat profile of APT29 (Cozy Bear), a Russian state-sponsored cyber espionage group targeting Western governments, defence, and critical infrastructure with persistent, stealthy campaigns.
A threat profile of APT28 (Fancy Bear), a Russian military intelligence-backed threat actor known for cyber espionage, disinformation, and targeted attacks on NATO, the UK, and global political infrastructure.
A threat profile of APT10, a Chinese state-sponsored cyber espionage group known for global targeting of managed service providers, defence contractors, and research institutions through advanced supply chain compromise and credential theft.
A threat profile of Anonymous, the decentralised hacktivist collective known for ideologically driven cyber operations, including DDoS attacks, data leaks, and defacement campaigns against governments and corporations.
A detailed threat profile of Akira, a ransomware group active since 2023 that targets organisations with double extortion attacks and cross-platform capabilities.
A threat profile of 8Base, a rapidly expanding ransomware group known for double extortion tactics, opportunistic targeting, and the re-use of leaked ransomware infrastructure.
Scaling Threat Hunting with Automation and Orchestration: how organisations effectively scale threat-hunting capabilities.
Real-World Threat Hunting Scenarios we highlight practical applications of the techniques and tools we've previously discussed
Essential Tools & Techniques for Effective Threat Hunting - We delve into the essential tools & techniques of any successful threat-hunting
216 articles · page 17 of 18