G0059: Magic Hound
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.CitationFireEye APT35 2018CitationClearSky Kittens Back 3 August 2020CitationCertfa Charming Kitten January 2021CitationSecureworks COBALT ILLUSION Threat ProfileCitationProofpoint TA453 July2021
Security context for executives and security teams
Magic Hound matters because MITRE describes it as a long-running, resource-intensive Iranian-sponsored cyber espionage group using complex social engineering against government, military, academic, journalist, and health-related targets. For leaders, the practical risk is not only malware execution; it is the combination of human targeting, credential theft, discovery, and remote access behaviors that can turn a successful lure into sustained access to sensitive people, accounts, and systems.
Executive priority
Prioritize this as an identity, endpoint, and incident-readiness problem for organizations with exposed executives, researchers, policy, defense, media, health, or regional interests. Ask whether high-risk users have phishing-resistant account protections, whether credential dumping and remote administration activity would be visible, and whether incident response can quickly determine which accounts, hosts, and sensitive files were accessed after a social-engineering-led intrusion.
Technical view
ATT&CK does not provide group-level tactics, platforms, or detection text for this object, so validation should be driven by the related techniques and software. Relationships show use of Windows-oriented credential and admin tooling such as Mimikatz, PsExec, Net, ipconfig, netsh, CharmPower, and PowerLess; cross-platform tools such as Pupy, Impacket, and FRP; and techniques including LSASS Memory, local data collection, network and user discovery, RDP, command obfuscation, and encoded files. SOC teams should test whether they can correlate social-engineering entry indicators with endpoint process execution, PowerShell activity, credential access attempts, RDP logons, discovery commands, and proxy or remote-access tooling.
Likely telemetry
- Email, web, and collaboration security logs for social-engineering delivery and suspicious links where available
- Identity provider and authentication logs, including unusual sign-ins, MFA events, and account takeover indicators
- Endpoint process creation and command-line telemetry for Net, ipconfig, netsh, systeminfo, ping, PowerShell, PsExec-like execution, and obfuscated commands
- Windows security and EDR events related to LSASS access or credential dumping behavior
- RDP logon records, lateral movement indicators, and administrative remote execution activity
Detection direction
- Do not rely on a single Magic Hound signature; ATT&CK provides no official detection guidance for this group object.
- Prioritize behavior chains: social engineering or credential activity followed by discovery commands, LSASS access, RDP, PsExec/Impacket-style remote execution, and data staging or local file access.
- Tune carefully for legitimate administration tools. Net, PsExec, ping, ipconfig, netsh, systeminfo, RDP, and Impacket-like activity may be benign in admin contexts, so detections should include user, host role, time, parent process, command-line, and remote peer context.
- Validate PowerShell visibility because related software includes PowerShell-based modular backdoors CharmPower and PowerLess.
- Review blind spots around personal or third-party communications channels, unmanaged devices, and high-risk individuals, since the official description emphasizes complex social engineering and targeting of people as well as organizations.
Mitigation priorities
- Start with high-risk user protection: phishing-resistant MFA where feasible, strong account recovery controls, and security awareness focused on targeted social engineering.
- Reduce credential theft impact by limiting local admin rights, protecting privileged accounts, and monitoring or restricting access to LSASS where supported by the environment.
- Harden and monitor remote administration paths such as RDP, PsExec-style execution, and administrative shares; restrict exposure and require strong authentication.
- Improve endpoint logging for command-line, PowerShell, script execution, and credential access events before relying on advanced analytics.
- Segment sensitive research, policy, executive, and operational systems so a compromised user account does not provide broad discovery or lateral movement paths.
Additional notes and limits
The strongest decision value comes from the relationship context: Magic Hound is associated with credential dumping, discovery, remote access, obfuscation, local data collection, and multiple dual-use or open-source tools. The group also consolidates the revoked Charming Kitten object, so defenders should map historical reporting names such as TA453, APT35, Phosphorus, COBALT ILLUSION, Newscaster, and Mint Sandstorm when searching threat intelligence and internal cases.
ATT&CK supplies no official detection text, no group-level platforms, and no group-level tactics for this object. The take therefore avoids claiming detection coverage or current exploitation and uses only the supplied description, references, aliases, and relationships. Local telemetry, asset exposure, user risk, and business mission context are required to determine actual priority.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Magic Hound
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.CitationFireEye APT35 2018CitationClearSky Kittens Back 3 August 2020CitationCertfa Charming Kitten January 2021CitationSecureworks COBALT ILLUSION Threat ProfileCitationProofpoint TA453 July2021
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
