◇ SIGN IN
← all actors
apt

Ballistic Bobcat

activehigh confidence
APT / State-sponsored
APT35APT42Charming KittenTA453PHOSPHORUSMint Sandstorm
Attribution
Iran — IRGC-aligned (Charming Kitten cluster)
Origin
Iran
First seen
2021
Last active
2024
Motivation
Espionage
Confidence
high
MENA targeting
Israel (primary), broader Middle East
Sectors
Automotive, manufacturing, engineering, finance, media, healthcare, tech, telecom
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Israel (primary), broader Middle East (Automotive, manufacturing, engineering sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Ballistic Bobcat is ESET's designation for an Iran-aligned Charming Kitten-related cluster conducting cyber-espionage, best known for the C++ 'Sponsor' backdoor campaign that predominantly struck Israeli organizations.

History

Ballistic Bobcat is the name ESET Research uses for an Iran-aligned APT it previously tracked as part of the APT35/APT42 (Charming Kitten / TA453 / PHOSPHORUS) ecosystem. It conducts cyber-espionage against education, government, healthcare, technology, and financial targets, as well as human-rights activists and journalists, consistent with IRGC intelligence priorities. Because ESET's clustering overlaps with several vendors' Charming Kitten labels, precise boundaries between Ballistic Bobcat and sibling clusters carry some attribution uncertainty.

The group commonly gains initial access by exploiting known vulnerabilities in internet-exposed servers (a 'scan-and-strike' pattern) before deploying custom malware. In September 2023 ESET detailed its 'Sponsor' backdoor — a C++ implant that collects host information and executes remote commands, with deployment dating back to at least September 2021 and configuration files used to evade detection.

MENA targeting is dominated by Israel. Of the 34 victims in the ESET-named 'Sponsoring Access' campaign, the large majority were Israeli organizations across automotive, manufacturing, engineering, financial services, media, healthcare, technology, and telecom, with only isolated victims in Brazil and the UAE. Notably, ESET observed that many victims were accessed by more than one threat actor, suggesting shared or brokered access within the Iranian ecosystem.

Ballistic Bobcat's activity is assessed as continuing under the broader Charming Kitten / APT42 umbrella, which multiple vendors report as highly active against Israeli and regional targets through 2024–2025; standalone 'Ballistic Bobcat'-branded reporting is most prominent through 2023–2024.

Notable campaigns

2021
Sponsor backdoor deployment
Earliest observed use of the C++ Sponsor implant against Israeli and regional targets via vulnerable internet-facing servers.
2023
Sponsoring Access campaign
ESET-documented espionage against 34 victims, overwhelmingly Israeli, using the Sponsor backdoor.