Cyber Resilience

Threat actor · all actors

Magic HoundG0059 state

🇮🇷 IR · IRGC

aka Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm, Newscaster Team, G0059, TunnelVision, COBALT MIRAGE, Agent Serpens

Last updated: 2026-07-03

0attributed CVEs
109ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Secureworks COBALT ILLUSION Threat Profile)(Citation: Proofpoint TA453 July2021)

Source: MITRE ATT&CK

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-463 / 10958%
CM-655 / 10950%
CM-247 / 10943%
SI-344 / 10940%
AC-339 / 10936%
CM-739 / 10936%
CA-737 / 10934%
AC-636 / 10933%
AC-235 / 10932%
AC-433 / 10930%
SC-731 / 10928%
SI-730 / 10928%
AC-526 / 10924%
IA-225 / 10923%
CM-522 / 10920%

Co-occurring actors

None.

Similar actors

Similar TTPs

Same nation-state