The BellaCiao operators are a Charming Kitten-linked Iranian cluster that deploys the customized, per-target BellaCiao dropper and its BellaCPP C++ variant to establish stealthy long-term persistence in victim networks, including Middle Eastern targets in Turkey.
BellaCiao was first documented by Bitdefender in April 2023 as a custom dropper attributed to Charming Kitten (APT35 / Magic Hound / Phosphorus), the IRGC-aligned Iranian espionage cluster that MITRE tracks as Magic Hound (G0059). The 'BellaCiao operators' label refers to the activity set built around this malware family rather than a formally distinct named group; attribution to the broader Charming Kitten ecosystem is well supported, while sub-cluster boundaries remain fluid.
BellaCiao is notable for being tailored to each individual target, indicating deliberate reconnaissance before deployment. On execution it attempts to disable Microsoft Defender via PowerShell, achieves persistence through a new service, and downloads IIS web-shell backdoors. Its signature C2 technique is a daily DNS request resolving a subdomain to an IP address, from which encoded instructions are parsed — a low-noise channel designed to evade network monitoring.
Geographic targeting spans the U.S., Europe, India, and the Middle East. Within MENA, reporting places victims in Turkey, and the actor's parent cluster is heavily engaged against Israeli and regional targets. In late 2024 researchers documented BellaCPP, a C++ variant distributed as a DLL that drops the web-shell component in favor of establishing covert SSH tunnels, reflecting continued tooling evolution toward stealthier persistence.
The operators are assessed as active within the Charming Kitten / APT35 umbrella through 2024, with BellaCPP demonstrating ongoing development. As with related Charming Kitten clusters, activity is consistent with IRGC intelligence-collection objectives during heightened regional tensions.