logo

GreenCharlie Infrastructure Linked to US Political Campaign Targeting

ID: b76e0e21-a5f2-49aa-8e88-5efbfa0aa91d

STIX ID: report--b76e0e21-a5f2-49aa-8e88-5efbfa0aa91d

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2024-08-19

Last Modified Date: 2024-08-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future’s Insikt Group identifies and tracks a cluster of Iran-linked malicious infrastructure attributed to a group it calls GreenCharlie, which overlaps with Mint Sandstorm/Charming Kitten/APT42. The report links GreenCharlie infrastructure to malware (GORBLE, POWERSTAR/CharmPower, TAMECAT) used in spearphishing campaigns targeting research, policy, diplomatic, and US political campaign-related targets; provides network intelligence, hosting/registrar patterns, ProtonVPN usage, IoCs (numerous DDNS domains, IPs, Iran-based IPs, and malware hashes), and ATT&CK technique mappings.