not MITRE’s Revoked by ATT&CK
Charming Kitten
How MITRE ATT&CK characterizes this group1: Charming Kitten is an Iranian cyber espionage group that has been active since approximately 2014. They appear to focus on targeting individuals of interest to Iran who work in academic research, human rights, and media, with most victims having been located in Iran, the US, Israel, and the UK. [Charming Kitten often tries to access private email and Facebook accounts, and sometimes establishes a foothold on victim computers as a secondary objective. The…
Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.
Read as a state-directed operator, not a smash-and-grab.
A nation-state classification means patience, tradecraft, and an intelligence objective. When this name attaches to a vulnerability, the question shifts from “will someone exploit it” to “has a well-resourced service already built it into an operation.” All tradecraft below is sourced to MITRE ATT&CK.
Known for
— signature moves, each sourced to ATT&CKTradecraft heatmap
— ATT&CK techniques mapped onto the five attacker-outcome narrativesNo techniques are recorded for this group in the ATT&CK snapshot below — the tradecraft heatmap is empty. That is an honest coverage gap (sparse / legacy / revoked group), never a claim that the actor does nothing.1
Arsenal
— named tools & malware ATT&CK attributes to this groupATT&CK attributes no software to G0058 at this snapshot. Absence is a finding, not a claim of harmlessness.
Campaign highlights
— attributed operations in the ATT&CK recordNo attributed campaigns — coverage gap
Latest activity
— with explicit confidence, and what we cannot yet claimsnapshot
The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.