Hackers' new stealthy tactic: gaining trust before stealing secrets
Iranian hackers known as Charming Kitten have found an insidious way to pilfer sensitive information from even the most secure targets without exploiting vulnerabilities or deploying sophisticated malware.
It all starts with trust-building
Unlike traditional cyber-attacks, which often begin with a malicious file or a compromised website, Charming Kitten's operation starts much earlier. The group initiates contact by posing as credible profiles, such as journalists, researchers, or industry professionals relevant to the target victim.
This initial outreach has no technical component; it's simply a well-crafted, normal conversation filled with real references and coherent language. The goal is to eliminate any suspicion and establish a seemingly legitimate relationship.
Charming Kitten often invests time in researching the individual beforehand to tailor their approach and make it more convincing – a crucial step that sets them apart from mass attacks.

How the attack unfolds, step by step
Once the contact is established, the hacker's attack evolves gradually. The next step usually involves introducing an element into the conversation – a shared document, an invitation to collaborate, or access to an external platform.
This 'entry point' could redirect the user to a fake page designed to capture credentials, mimicking well-known services with great precision. In other cases, the attachment contains code that executes when opened, allowing malicious software to be installed without the user's awareness.
The attackers wait for the victim to act naturally, without pressure, to reduce the likelihood of detection while increasing the chances of success.

The ultimate goal: espionage
These campaigns are geared towards espionage, aiming to obtain access credentials, emails, documents, or any data of value. Typically, the victims are individuals with access to sensitive or relevant information, such as researchers, journalists, tech industry employees, or those connected to key sectors.
Once the attacker gains access, they can maintain a presence for an extended period, observing communications or extracting data without generating obvious signs.
This method is especially dangerous because it can bypass even the most up-to-date, protected systems if the user trusts the wrong source. Even the best antivirus software and security tools are designed to detect anomalous behavior or suspicious files, but in this case, much of the process occurs within legitimate interactions, making it harder to spot the deception.

No os is immune
This type of attack doesn't distinguish between operating systems, making both Apple and Windows userspotential targets. This dismantles the common assumption that no system is secure if the access comes through the user themselves. The protection becomes less decisive when the door opens from within.
Charming Kitten's tactics are not groundbreaking in terms of new tools but rather a sophisticated application of Cold War-era methods in today's digital landscape. The combination of identity spoofing, prolonged contact, and manipulation turns a conversation into the most effective entry point.
