Ballistic Bobcat is ESET's designation for an Iran-aligned Charming Kitten-related cluster conducting cyber-espionage, best known for the C++ 'Sponsor' backdoor campaign that predominantly struck Israeli organizations.
Ballistic Bobcat is the name ESET Research uses for an Iran-aligned APT it previously tracked as part of the APT35/APT42 (Charming Kitten / TA453 / PHOSPHORUS) ecosystem. It conducts cyber-espionage against education, government, healthcare, technology, and financial targets, as well as human-rights activists and journalists, consistent with IRGC intelligence priorities. Because ESET's clustering overlaps with several vendors' Charming Kitten labels, precise boundaries between Ballistic Bobcat and sibling clusters carry some attribution uncertainty.
The group commonly gains initial access by exploiting known vulnerabilities in internet-exposed servers (a 'scan-and-strike' pattern) before deploying custom malware. In September 2023 ESET detailed its 'Sponsor' backdoor — a C++ implant that collects host information and executes remote commands, with deployment dating back to at least September 2021 and configuration files used to evade detection.
MENA targeting is dominated by Israel. Of the 34 victims in the ESET-named 'Sponsoring Access' campaign, the large majority were Israeli organizations across automotive, manufacturing, engineering, financial services, media, healthcare, technology, and telecom, with only isolated victims in Brazil and the UAE. Notably, ESET observed that many victims were accessed by more than one threat actor, suggesting shared or brokered access within the Iranian ecosystem.
Ballistic Bobcat's activity is assessed as continuing under the broader Charming Kitten / APT42 umbrella, which multiple vendors report as highly active against Israeli and regional targets through 2024–2025; standalone 'Ballistic Bobcat'-branded reporting is most prominent through 2023–2024.