PULSE NAME
The APT35 Dump Episode 4: Leaking The Backstage Pass To An Iranian Intelligence Operation
WHITE Tr1sa111 2025-12-18 Modified: 2026-01-17
21
IOCs
MEDIUM VOLUME
APT35, also known as Charming Kitten, has long occupied an odd niche in the hierarchy of Iranian cyber operations. They’re the loud ones, constantly deploying new credential-harvesting pages dressed in Western university or defense-contractor branding, yet always recycling the same code and lures. For years, analysts dismissed them as a politically motivated collective within the Revolutionary Guard’s orbit, dangerous mainly to journalists and dissidents, but rarely haunting MITRE’s nightmares
Indicators of Compromise (21)
All domain email
TYPEINDICATORDESCRIPTIONCREATED
domain bbmovements.com 2025-12-18
domain cavinet.org 2025-12-18
domain dreamy-jobs.com 2025-12-18
domain israel-talent.com 2025-12-18
domain israel-talent.xyz 2025-12-18
domain kanplus.org 2025-12-18
domain secnetdc.com 2025-12-18
domain tecret.com 2025-12-18
domain termite.nu 2025-12-18
domain wazayif-halima.org 2025-12-18
domain moses-staff.io 2025-12-18
domain moses-staff.se 2025-12-18
email b.laws32@proton.me 2025-12-18
email bashiriansul@proton.me 2025-12-18
email gdavies007@proton.me 2025-12-18
email jhjbmuugtfftdd@proton.me 2025-12-18
email lolita259@proton.me 2025-12-18
email mekhaeelkalashnikova@proton.me 2025-12-18
email rona_yanga@proton.me 2025-12-18
email sanjilankopylova@proton.me 2025-12-18
email shirley7070@proton.me 2025-12-18