Persona, Infrastructure & Access: An Operational Case Study Attributed to "APT35"
Classification: TLP:AMBER — Internal threat-intel working notes
Source material: 20 daily reports + 1 monthly rollup + 1 attendance log, Farsi-language, operator “Majid,” project “Campaign,” Aug 17–Oct 15 2024 (Jalali 1403/06/25–1403/07/23)
Attribution note: The “APT35” label comes from the analyst’s own case folder naming, not from independent confirmation in this write-up. Overlaps with publicly reported Charming Kitten/APT35 (aka Phosphorus/TA453/Mint Sandstorm) tradecraft are marked explicitly as analytical correlation, separate from what the source documents state directly.
Why this matters
Most APT reporting reconstructs tradecraft after the fact, from telemetry and IOCs. This source is different: it’s the operator’s own timesheet — mundane, hour-logged, occasionally exasperated (“no response from support yet”) — which makes it unusually good ground truth for how the operation was actually built, day by day, tool by tool.
1. Persona and account infrastructure
The operator’s first two weeks are almost entirely about building durable, verifiable-looking online identities:
- Skype — compared “local number” vs. “phone number” products before buying a paid number with exchange-sourced credit.
- Microsoft account recovery cycles — the Skype/Microsoft account was suspended almost immediately after password/security changes, requiring repeated support tickets to recover.
- Facebook Business/Ads — hit a recurring “prefund” payment block; tried switching the account’s declared region (Nigeria specifically) to unlock prepaid billing, without success. Card issues also arose from a name mismatch between the linked card and the Microsoft account’s registered name (“kaela jenkinz”), which got a Microsoft ad account suspended for suspected fraud.
- Domain/hosting stack — Namecheap and NameSilo for domain purchases, Cloudflare in front of the domain, cPanel/FTP for the host. A front template site,
aecars.store, was uploaded, translated into Arabic, debugged for display/redirect issues, and given arobots.txtto look legitimate to search engines. Google Search Console and Bing Webmaster Tools were connected to the domain for the same reason. - SnappPay — a separate follow-up thread with SnappPay support (an Iranian BNPL/payment-gateway service) runs alongside the Facebook/Microsoft payment work, suggesting the operator was testing multiple regional payment rails in parallel, not just Western ones.
- Google Ads / Google Analytics — wired up to the front domain to run and track ad campaigns.
- Host reinstall — the host’s network card failed on the previously installed instance and had to be reinstalled from scratch; afterward, the operator downloaded the latest versions of Photoshop and Dreamweaver to resume template/image work — Dreamweaver in particular indicates direct hand-editing of the front site’s HTML/CSS, not just template reuse.
- Trust Pilot — used as a vetting layer: the operator cross-checked candidate vendor sites (SMS panels, VPNs, card providers) against Trust Pilot reviews before committing money, reviewing more than 50 different sites and their ratings before shortlisting.
Analytical correlation: This mirrors the “Mia Ash” persona operation publicly attributed to Charming Kitten (SecureWorks, 2017) — a long-cultivated, multi-platform fake identity used to build trust with employees at a target organization before pivoting to credential theft. The pattern here (patient persona-building across Facebook/Twitter/LinkedIn/Telegram, treated as its own project with its own KPIs) is structurally the same playbook, just captured mid-build rather than after deployment.
2. Identity-verification and payment evasion
- Physical SIM cards and eSIMs — purchased using ID documents bought for this purpose; roaming-network registration repeatedly failed across 4–5 different carriers before finally connecting.
- Payment rails: PayPal, Wise, virtual Visa/Mastercard, and an Atomic Wallet funded with Ethereum. The operator swapped currency directly from the Atomic Wallet balance and coordinated again with the wallet’s Ethereum support to get a receiving address for topping up SMS-panel purchases — a multi-step process, not a one-click payment. coinsbee (a crypto-to-gift-card gateway) was used to buy a ChatGPT Plus subscription with crypto for the same reason: avoiding card-based KYC.
- Document purchase — explicit line items for buying identity documents to support SIM, VPN, and payment-account registration.
- VPN services — evaluated specifically for ones accepting crypto instead of card-linked identity verification.
SMS/OTP panel evaluation — MessageBird vs. Telnyx
This is the most tool-dense decision point in the dataset. Starting from a Trust-Pilot-filtered shortlist of over 50 candidates, the operator narrowed to eight commercial SMS/OTP-API vendors: MessageBird, Telnyx, Simpletext, ClickSend, seven.io, smsala, Vonage, and smsbeep. Two got dedicated head-to-head testing:
- MessageBird — tested and rejected. The source is explicit: the panel “was not found to be of high quality” — i.e., the rejection was on service quality/reliability grounds, not on identity-verification friction.
- Telnyx — the stronger candidate. Rated good quality with excellent reviews, but it requires two-way identity verification (KYC) before use — the exact friction the operator was trying to avoid everywhere else in this workstream (crypto payments, prepaid billing switches, document purchases). This creates a direct tension in the operator’s own tasking: the best-performing panel is also the one hardest to onboard to anonymously, and the daily logs show the operator still weighing it against the KYC-light alternatives (Simpletext, ClickSend, seven.io, smsala, Vonage) rather than committing immediately.
That tension — quality vs. anonymity — is arguably the single clearest signal in the whole dataset of what the operator’s actual constraint is: not technical capability, but staying unattributable while sourcing bulk verified phone numbers.
3. Content operations and distribution
- Telegram — primary distribution channel. Channels branded under at least two distinct personas (“aminkhalij” and “society,” with swapped logos), targeting Persian Gulf/UAE-focused advertising channels and groups specifically.
- Automated scheduling at volume — work was done to create 120 posts for automatic scheduled publishing across the accounts, of which 35 were ready in the same session; the remaining content was sourced by reviewing Instagram and Pinterest to select suitable photos/material rather than producing everything from scratch.
- Engagement inflation — explicit tasking to boost “likes and comments” to manufacture organic-looking traction.
- AI content tooling: Lumen5 (AI video generation) evaluated and used for ad creative; six AI video tools compared, three tested for motion-graphic ads. Photoshop and Dreamweaver used for image and site-template editing respectively.
Analytical correlation: Coordinated inauthentic content pipelines feeding sock-puppet persona networks are a documented Charming Kitten/IRGC-adjacent technique (see Meta and Google TAG takedowns of Iran-linked influence networks, 2021–2023), typically used to build audience trust ahead of a social-engineering pivot rather than as an end in itself — consistent with this dataset’s parallel reconnaissance track (§4).
4. Reconnaissance against a named target
Starting Mehr 11 (Oct 2, 2024), the workstream shifts to sustained OSINT against a target referred to as “iasa,” matching iasa.co.org, school.iasa.co.org, and library.iasa.co.org — internally called “ice-iasa.” Per the source:
“OSINT work was also carried out on the targets iasa.co.org, school.iasa.co.org, library.iasa.co.org, etc., which have numerous other associated websites (all under the ‘iasa’ name and relating to the same educational organization). At present the three named websites have been fully scanned and their usernames obtained; however, since they are associated with the name ‘ice-iasa,’ more time is needed for a supplementary report (time available for this work is limited). Vulnerabilities present in the web server, WordPress, and even their database methods, along with existing exploitable weaknesses, have also been identified. Also, two Telegram channels for …” (source text truncated at this point)
Independently, the daily logs confirm the target is a university (“it too is a university and has educational activity”), and that a dedicated OS/VM environment was rebuilt for this work, with VeraCrypt used to encrypt the VM disks (basic operator-side OPSEC) and CEH (Certified Ethical Hacker) training material referenced to help write up the completed report.
Analytical correlation: Academia — especially institutions with library/school-branded subdomains implying a research or educational footprint — is a well-documented Charming Kitten target category. This is circumstantial, not confirmed: the real-world identity of “iasa.co.org” and whether the described scan/vulnerability findings represent an active, unremediated compromise has not been independently verified here.
5. Parallel malware-development track (“RTM” project)
Reported separately by a second operator (“Hossein”) in the same overall timeframe, the RTM project describes:
- An Active Directory share-folder enumerator (MITRE ATT&CK T1135, Network Share Discovery).
- A file-rewrite/infection capability for shares with high-level write access (T1080, Taint Shared Content).
- A lab Active Directory domain stood up purely to test RTM, with repeated failures joining Windows Server clients — a signal of a junior/solo developer, not a mature dev team.
- A loader gaining shell access and arbitrary-binary execution via a command-line switch (T1059, T1204).
- A “system info” + ACK beacon, later extended to a per-user “send status” function so the C2 server logs each victim’s status on every binary execution.
Analytical correlation: No match to any named, publicly documented APT35 malware family (POWERSTAR, BellaCiao, POWERLESS, GhostTown/Sponsor) — all are markedly more mature than what’s described here. The more defensible read is early-stage, in-house tooling built alongside the social-engineering-heavy persona operation, not a variant of a known implant.
6. Assessment
- Operational maturity is uneven and telling. Persona/infrastructure tradecraft (KYC evasion, payment laundering via crypto, content-distribution automation, careful vendor vetting via Trust Pilot) is fluent and well-practiced. Malware development (RTM) is visibly junior. This lines up with the broader public picture of Charming Kitten as a cluster that leans on trust-building and legitimate-service abuse over custom exploit development.
- The MessageBird/Telnyx decision encapsulates the operation’s core bottleneck: not technical skill, but sourcing verified phone numbers at volume without surfacing a traceable identity. Quality and anonymity trade off directly, and the logs show the operator still undecided between them.
- This reads as a small paid team, not a lone actor. Two named operators (“Majid,” “Hossein”), a “management” role that assigns tasks and holds Thursday meetings, and hour-logged timesheets with per-task time estimates.
- Location signal: use of SnappPay and Snapp Food (Iran-only services) is a strong indicator the operator is physically based in Iran.
- The “iasa” university target deserves independent verification. If this is a live, unremediated compromise (harvested usernames + identified web/DB vulnerabilities, per the source), that’s actionable now — worth confirming the real-world identity of the domain and considering responsible disclosure.
Indicators referenced in source material (unverified, for tracking only)
- Domain:
aecars.store - Target domains:
iasa.co.org,school.iasa.co.org,library.iasa.co.org(internal name “ice-iasa”) - Infra/services: Namecheap, NameSilo, Cloudflare, cPanel, SnappPay — Skype, Microsoft 365 — Facebook Ads/Business, Google Ads/Analytics/Search Console, Bing Webmaster — Telegram (personas “aminkhalij,” “society”), Instagram, Pinterest
- SMS/OTP panels: MessageBird (rejected, low quality), Telnyx (high quality, requires KYC), Simpletext, ClickSend, seven.io, smsala, Vonage, smsbeep
- Payment/wallets: Atomic Wallet (Ethereum), coinsbee, PayPal, Wise
- Tooling: Lumen5, Photoshop, Dreamweaver, Trust Pilot, VeraCrypt