Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Magic Hound, APT 35, Cobalt Illusion, Cobalt Mirage, Charming Kitten, TEMP.Beanie, Timberworm, Tarh Andishan, TA453, Phosphorus, TunnelVision, UNC788, Yellow Garuda, Educated Manticore, Mint Sandstorm, Ballistic Bobcat, CharmingCypress, Agent Serpens, G0058, G0059, Newscaster Team, COBALT MIRAGE, CALANQUE, Newscaster, Parastoo, iKittens, Group 83, NewsBeef, PHOSPHORUS, APT35, Operation Cleaver, Op Cleaver, Alibaba, TG-2889, Cobalt Gypsy, G0003, Hazel Sandstorm, EUROPIUM, APT34, OilRig, CHARMING KITTEN, ITG-018, SpearSpecter, Threat Group 2889, COBALT ILLUSION, TA455, ITG18
Magic Hound is an Iranian-sponsored threat group operating primarily in the Middle East that dates back as early as 2014. The group behind the campaign has primarily targeted organizations in the energy, government, and technology sectors that are either based or have business interests in Saudi Arabia. Magic Hound has 2 subgroups: 1. Subgroup: DEV-0270, Nemesis Kitten 2. Subgroup: TA455, Smoke Sandstorm This group appears to be the evolvement of Cutting Kitten, TG-2889 . There is some infrastructure overlap with Rocket Kitten, Newscaster, NewsBeef , ITG18 and APT 42 .
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database