◇ SIGN IN
← all actors
apt

BellaCiao operators (Charming Kitten-linked)

activemedium confidence
APT / State-sponsored
Charming KittenAPT35Magic HoundPhosphorusMint Sandstorm
Attribution
Iran — IRGC-aligned (Charming Kitten cluster)
Origin
Iran
First seen
2023
Last active
2024
Motivation
Espionage
Confidence
medium
MENA targeting
Israel, Turkey (MENA subset of a wider campaign; source also lists Austria, India, Italy, and US/Europe victims)
Sectors
Cross-sector
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Israel, Turkey (MENA subset of a wider campaign; source also lists Austria, India (Cross-sector sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

The BellaCiao operators are a Charming Kitten-linked Iranian cluster that deploys the customized, per-target BellaCiao dropper and its BellaCPP C++ variant to establish stealthy long-term persistence in victim networks, including Middle Eastern targets in Turkey.

History

BellaCiao was first documented by Bitdefender in April 2023 as a custom dropper attributed to Charming Kitten (APT35 / Magic Hound / Phosphorus), the IRGC-aligned Iranian espionage cluster that MITRE tracks as Magic Hound (G0059). The 'BellaCiao operators' label refers to the activity set built around this malware family rather than a formally distinct named group; attribution to the broader Charming Kitten ecosystem is well supported, while sub-cluster boundaries remain fluid.

BellaCiao is notable for being tailored to each individual target, indicating deliberate reconnaissance before deployment. On execution it attempts to disable Microsoft Defender via PowerShell, achieves persistence through a new service, and downloads IIS web-shell backdoors. Its signature C2 technique is a daily DNS request resolving a subdomain to an IP address, from which encoded instructions are parsed — a low-noise channel designed to evade network monitoring.

Geographic targeting spans the U.S., Europe, India, and the Middle East. Within MENA, reporting places victims in Turkey, and the actor's parent cluster is heavily engaged against Israeli and regional targets. In late 2024 researchers documented BellaCPP, a C++ variant distributed as a DLL that drops the web-shell component in favor of establishing covert SSH tunnels, reflecting continued tooling evolution toward stealthier persistence.

The operators are assessed as active within the Charming Kitten / APT35 umbrella through 2024, with BellaCPP demonstrating ongoing development. As with related Charming Kitten clusters, activity is consistent with IRGC intelligence-collection objectives during heightened regional tensions.

Notable campaigns

2023
BellaCiao multi-country campaign
Bitdefender-documented deployment of per-target BellaCiao droppers across the US, Europe, Middle East (Turkey), and India.
2024
BellaCPP variant
C++ rewrite dropping web-shell functionality in favor of covert SSH tunneling for stealthier persistence.