GreenCharlie Infrastructure Linked to US Political Campaign Targeting
ID: b76e0e21-a5f2-49aa-8e88-5efbfa0aa91d
STIX ID: report--b76e0e21-a5f2-49aa-8e88-5efbfa0aa91d
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2024-08-19
Last Modified Date: 2024-08-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future’s Insikt Group identifies and tracks a cluster of Iran-linked malicious infrastructure attributed to a group it calls GreenCharlie, which overlaps with Mint Sandstorm/Charming Kitten/APT42. The report links GreenCharlie infrastructure to malware (GORBLE, POWERSTAR/CharmPower, TAMECAT) used in spearphishing campaigns targeting research, policy, diplomatic, and US political campaign-related targets; provides network intelligence, hosting/registrar patterns, ProtonVPN usage, IoCs (numerous DDNS domains, IPs, Iran-based IPs, and malware hashes), and ATT&CK technique mappings.
