dti.domaintools.com 6/22/2026, 11:40:46 PM · external

Leaked files show APT35 runs like a government department

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

APT 35, or Charming Kitten, represents a bureaucratic structure mimicking a hacker collective within Iranian cyber operations. Their latest leak exposes operational mechanics, revealing how espionage is administered with administrative diligence rather than rogue ingenuity. The leaked files highlight expense reports detailing the infrastructure behind phishing and cyber-espionage, not just the flashy front of hacking.

APT35 fails basic operational security, revealing their infrastructure to scrutiny over an extended period. The insights showcase how Iran’s cyber strategy turns state intent into actionable operations through meticulous financial management, reinforced by a robust bureaucratic system. This threat actor operates like a governmental department, with logistics closely tied to budget management, leading to targeted operations that leverage psychological warfare against Israel without direct military confrontation.

View full article

Article by CyberSIXT