Cyber Resilience

Threat actor · all actors

Magic HoundG0059 state

🇮🇷 IR · IRGC

aka Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm, Newscaster Team, G0059, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, Parastoo, iKittens, Group 83, NewsBeef, G0058, CharmingCypress

Last updated: 2026-08-20

0attributed CVEs
109ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Secureworks COBALT ILLUSION Threat Profile)(Citation: Proofpoint TA453 July2021)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0059G0058

Microsoftweather-system names

Mint Sandstorm

CrowdStrikenation-animal names

Charming KittenAgent Serpens

Mandiant / genericAPT numbering

APT35

Secureworkscolour-metal names

COBALT ILLUSIONCOBALT MIRAGE

DragosICS mineral names

Phosphorus

ProofpointTA threat-actor id

TA453

Unclassifiedno scheme matched

Magic HoundITG18NewscasterNewscaster TeamTunnelVisionRICH IONParastooiKittensGroup 83NewsBeefCharmingCypress

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 109 ATT&CK techniques on file.
Named victims
1 extracted from reporting.

Thin data: Only one named victim is on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-463 / 10958%
CM-655 / 10950%
CM-247 / 10943%
SI-344 / 10940%
AC-339 / 10936%
CM-739 / 10936%
CA-737 / 10934%
AC-636 / 10933%
AC-235 / 10932%
AC-433 / 10930%
SC-731 / 10928%
SI-730 / 10928%
AC-526 / 10924%
IA-225 / 10923%
CM-522 / 10920%

Co-occurring actors

None.

Similar actors

Similar TTPs

Same nation-state