APT42 (Charming Kitten) is an IRGC-aligned Iranian espionage and surveillance group specializing in resource-intensive social engineering and credential theft against government, military, academic, journalist, and dissident targets, with intensified focus on Israel and Gulf states.
Mandiant designated APT42 in 2022, describing an IRGC-Intelligence Organization-linked actor active since at least 2015 and closely related to the long-documented Charming Kitten / Magic Hound cluster (which MITRE tracks separately as Magic Hound, G0059). Vendors treat APT42, Charming Kitten, Mint Sandstorm, and TA453 as heavily overlapping labels for IRGC social-engineering operations; some behavioral and tooling overlaps exist while originating vendors track them as distinct entities.
The group's hallmark is patient, high-effort social engineering rather than mass phishing. Operators build rapport by impersonating journalists, conference organizers, academics, and NGO staff across email and messaging platforms, then steer targets to credential-harvesting pages and real-time 2FA/MFA interception. It also runs mobile surveillance, including the PINEFLOWER Android malware, to monitor targets' devices.
MENA operations center on Israel and the Gulf. Since April 2024, APT42 markedly increased targeting of Israeli government, military, aerospace, academic, journalist, and cybersecurity personnel. A 2025-reported campaign used WhatsApp with conference-themed lures and shortened URLs to spoofed sites harvesting email credentials and 2FA codes from Israeli security experts and academics — a deliberate, high-value targeting pattern.
APT42 is assessed as highly active into 2026. Google/Mandiant and multiple vendors have documented parallel election-interference and espionage operations against U.S. targets alongside the intensified Israel focus, consistent with IRGC intelligence priorities during heightened Iran-Israel tensions.