LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0059: Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.CitationFireEye APT35 2018CitationClearSky Kittens Back 3 August 2020CitationCertfa Charming Kitten January 2021CitationSecureworks COBALT ILLUSION Threat ProfileCitationProofpoint TA453 July2021

EnterpriseG0059GroupObject v6.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Magic Hound matters because MITRE describes it as a long-running, resource-intensive Iranian-sponsored cyber espionage group using complex social engineering against government, military, academic, journalist, and health-related targets. For leaders, the practical risk is not only malware execution; it is the combination of human targeting, credential theft, discovery, and remote access behaviors that can turn a successful lure into sustained access to sensitive people, accounts, and systems.

Executive priority

Prioritize this as an identity, endpoint, and incident-readiness problem for organizations with exposed executives, researchers, policy, defense, media, health, or regional interests. Ask whether high-risk users have phishing-resistant account protections, whether credential dumping and remote administration activity would be visible, and whether incident response can quickly determine which accounts, hosts, and sensitive files were accessed after a social-engineering-led intrusion.

Technical view

ATT&CK does not provide group-level tactics, platforms, or detection text for this object, so validation should be driven by the related techniques and software. Relationships show use of Windows-oriented credential and admin tooling such as Mimikatz, PsExec, Net, ipconfig, netsh, CharmPower, and PowerLess; cross-platform tools such as Pupy, Impacket, and FRP; and techniques including LSASS Memory, local data collection, network and user discovery, RDP, command obfuscation, and encoded files. SOC teams should test whether they can correlate social-engineering entry indicators with endpoint process execution, PowerShell activity, credential access attempts, RDP logons, discovery commands, and proxy or remote-access tooling.

Likely telemetry

  • Email, web, and collaboration security logs for social-engineering delivery and suspicious links where available
  • Identity provider and authentication logs, including unusual sign-ins, MFA events, and account takeover indicators
  • Endpoint process creation and command-line telemetry for Net, ipconfig, netsh, systeminfo, ping, PowerShell, PsExec-like execution, and obfuscated commands
  • Windows security and EDR events related to LSASS access or credential dumping behavior
  • RDP logon records, lateral movement indicators, and administrative remote execution activity

Detection direction

  • Do not rely on a single Magic Hound signature; ATT&CK provides no official detection guidance for this group object.
  • Prioritize behavior chains: social engineering or credential activity followed by discovery commands, LSASS access, RDP, PsExec/Impacket-style remote execution, and data staging or local file access.
  • Tune carefully for legitimate administration tools. Net, PsExec, ping, ipconfig, netsh, systeminfo, RDP, and Impacket-like activity may be benign in admin contexts, so detections should include user, host role, time, parent process, command-line, and remote peer context.
  • Validate PowerShell visibility because related software includes PowerShell-based modular backdoors CharmPower and PowerLess.
  • Review blind spots around personal or third-party communications channels, unmanaged devices, and high-risk individuals, since the official description emphasizes complex social engineering and targeting of people as well as organizations.

Mitigation priorities

  • Start with high-risk user protection: phishing-resistant MFA where feasible, strong account recovery controls, and security awareness focused on targeted social engineering.
  • Reduce credential theft impact by limiting local admin rights, protecting privileged accounts, and monitoring or restricting access to LSASS where supported by the environment.
  • Harden and monitor remote administration paths such as RDP, PsExec-style execution, and administrative shares; restrict exposure and require strong authentication.
  • Improve endpoint logging for command-line, PowerShell, script execution, and credential access events before relying on advanced analytics.
  • Segment sensitive research, policy, executive, and operational systems so a compromised user account does not provide broad discovery or lateral movement paths.
Additional notes and limits

The strongest decision value comes from the relationship context: Magic Hound is associated with credential dumping, discovery, remote access, obfuscation, local data collection, and multiple dual-use or open-source tools. The group also consolidates the revoked Charming Kitten object, so defenders should map historical reporting names such as TA453, APT35, Phosphorus, COBALT ILLUSION, Newscaster, and Mint Sandstorm when searching threat intelligence and internal cases.

ATT&CK supplies no official detection text, no group-level platforms, and no group-level tactics for this object. The take therefore avoids claiming detection coverage or current exploitation and uses only the supplied description, references, aliases, and relationships. Local telemetry, asset exposure, user risk, and business mission context are required to determine actual priority.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.CitationFireEye APT35 2018CitationClearSky Kittens Back 3 August 2020CitationCertfa Charming Kitten January 2021CitationSecureworks COBALT ILLUSION Threat ProfileCitationProofpoint TA453 July2021

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
6.1
Created
Modified
Raw hash
b29c155c46a77684...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.