Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0059
MITRE ATT&CK Group

Magic Hound (G0059)

TA453COBALT ILLUSIONCharming KittenITG18PhosphorusNewscasterAPT35Mint Sandstorm
ShareXLinkedInRedditHN

[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Secureworks COBALT ILLUSION Threat Profile)(Citation: Proofpoint TA453 July2021)

▪Techniques used (78)

T1056.001KeyloggingT1567Exfiltration Over Web ServiceT1589.001CredentialsT1547.001Registry Run Keys / Startup FolderT1059.001PowerShellT1016.002Wi-Fi DiscoveryT1588.002ToolT1584.001DomainsT1059.003Windows Command ShellT1572Protocol TunnelingT1585.002Email AccountsT1591.001Determine Physical LocationsT1071Application Layer ProtocolT1071.001Web ProtocolsT1486Data Encrypted for ImpactT1016.001Internet Connection DiscoveryT1586.002Email AccountsT1053.005Scheduled TaskT1592.002SoftwareT1021.001Remote Desktop ProtocolT1087.003Email AccountT1105Ingress Tool TransferT1190Exploit Public-Facing ApplicationT1204.002Malicious FileT1218.011Rundll32T1027.010Command ObfuscationT1046Network Service DiscoveryT1590.005IP AddressesT1113Screen CaptureT1573Encrypted ChannelT1059.005Visual BasicT1685.001Disable or Modify Windows Event LogT1595.002Vulnerability ScanningT1036.010Masquerade Account NameT1589.002Email AddressesT1204.001Malicious LinkT1102.002Bidirectional CommunicationT1033System Owner/User DiscoveryT1098.002Additional Email Delegate PermissionsT1070.004File DeletionT1027.013Encrypted/Encoded FileT1566.002Spearphishing LinkT1078.001Default AccountsT1083File and Directory DiscoveryT1016System Network Configuration DiscoveryT1036.005Match Legitimate Resource Name or LocationT1098.007Additional Local or Domain GroupsT1598.003Spearphishing LinkT1049System Network Connections DiscoveryT1114Email CollectionT1003.001LSASS MemoryT1570Lateral Tool TransferT1136.001Local AccountT1057Process DiscoveryT1114.002Remote Email CollectionT1571Non-Standard PortT1686.003Windows Host FirewallT1070.003Clear Command HistoryT1082System Information DiscoveryT1114.001Local Email CollectionT1505.003Web ShellT1090ProxyT1036.004Masquerade Task or ServiceT1583.001DomainsT1018Remote System DiscoveryT1112Modify RegistryT1482Domain Trust DiscoveryT1589Gather Victim Identity InformationT1078.002Domain AccountsT1566.003Spearphishing via ServiceT1560.001Archive via UtilityT1585.001Social Media AccountsT1564.003Hidden WindowT1005Data from Local SystemT1047Windows Management InstrumentationT1583.006Web ServicesT1685Disable or Modify ToolsT1189Drive-by Compromise

▪Software used (13)

S0039NettoolS0357ImpackettoolS0097PingtoolS0674CharmPowermalwareS1144FRPtoolS0002MimikatztoolS0096SysteminfotoolS0100ipconfigtoolS0108netshtoolS1012PowerLessmalwareS0192PupytoolS0186DownPapermalwareS0029PsExectool
G0059on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.