Magic Kitten is an Iranian-origin cyber threat group known for targeting political dissidents and opposition.
Analyst brief
Magic Kitten (also known as Group 42 and VOYEUR) is an established cyber threat group of Iranian origin, active since at least November 2008. The group primarily targets political opposition, dissidents, and opposition political parties, with notable campaigns in 2013 focused on individuals supporting Iranian political opposition. While specific TTPs and tools used are not detailed in the provided data, the target profile indicates a focus on long-term, targeted operations against individuals. Defenders should heighten their focus on spear-phishing campaigns, credential harvesting attempts, and persistent threat tactics directed at politically active persons.
Magic Kitten
Group 42VOYEUR
unknown
Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of attacks targeting political dissidents and those supporting Iranian political opposition.
What target profile does the Magic Kitten group (Group 42, VOYEUR) primarily select?+
Magic Kitten primarily targets political opposition, dissidents, and opposition political parties, particularly individuals supporting Iranian political opposition.
What threat tactics should defenders focus on against actors like Magic Kitten?+
Defenders should heighten their focus on spear-phishing campaigns, credential harvesting attempts, and persistent threat tactics directed at politically active persons.