The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Adversary5
Who is behind the activity — operator vs. customer.
Tradecraft, techniques, and tooling the adversary employs.
32 ATT&CK techniquesResource DevelopmentCollectionCommand and ControlDiscovery
Infrastructure
Physical/logical infrastructure used to deliver capability (C2, domains, relays).
No infrastructure indicators correlated in Radar yet.
Victim8
Targeting — sectors and geographies in scope.
GovernmentmediaNGOsacademiadissidents/activistsIsraelGulf statesbroader Middle East
Social-political (intent)Espionage
Operator ↔ CustomerOperator (intrusion crew) acting for a Customer (sponsoring interest) — attribution separates the two.
Honesty note
Attribution ≠ confirmation. This view assembles Charming Kitten / APT42's intrusions from tracked data and primary reporting (11 archived reports, MITRE G1044) — individual vertex links are analytic, not each independently confirmed. Treat it as an assessment, not a settled fact.
The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced. Export opens in CTID's Attack Flow Builder.
32 techniques across 7 of 7 stages · 6 of 6 pre-objective stages show known tradecraft — each a chance to break the chain before Actions on Objectives.
Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for Charming Kitten / APT42 — see the competing-hypotheses breakdown for how confident this attribution really is.