Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors APTIran

Also known as: Chafer, APT39, OilRig, Helix Kitten, MuddyWater, tracked as, Elfin, Refined Kitten, APT33, APT34, Hazel Sandstorm, Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Earth Simnavaz, is a sophisticated, UNC1549, Smoke Sandstorm, Iranian Dream Job, Advanced Persistent Threat 39, Cadelspy, Remexi, ITG07

Description

APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of government ministries, hospitals, universities, and financial institutions as retaliation for Israeli military operations. The group has leaked over 350,000 Israeli government login credentials and approximately 300 internal databases, while also threatening to create a 'zombie' network from infected devices. They have reportedly deployed ransomware strains such as ALPHV and LockBit as part of their offensive toolkit. Additionally, APTIran has made unverified claims of compromising Israeli water control systems and the state-owned food security agency Jordan Silos and Supply General Co.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Financial services
Aerospace
Critical infrastructure
Healthcare
Transportation
Energy
Manufacturing
Education
Hospitality
Oil gas
Utilities

Targeted Countries / Regions

IR
AE
IL
US
CN
SA
PK
BY
IQ
SY

AI Analysis

· 1 week ago

Executive Summary

APTVIran emerges as a significant cyber threat targeting Israeli critical infrastructure. The group claims to be retaliating against Israeli military operations through sophisticated cyberattacks, including ransomware deployment. Their activities highlight a growing trend of state-sponsored or politically motivated cyberattacks, posing substantial risks to national security and public services.

Goals & Targeting

APTVIran's primary objectives involve disrupting operations in critical sectors and creating public panic through threats of widespread infrastructure control. They target Israel, possibly due to geopolitical tensions or specific military-related grievances, focusing on entities that could cause maximum disruption and fear.

Enhanced Description

APTVIran is an active threat actor claiming responsibility for extensive cyberattacks on Israeli targets, notably critical infrastructure sectors such as government ministries, healthcare, education, and finance. The group has achieved substantial impact by infiltrating systems to leak sensitive information and deploy ransomware, including ALPHV and LockBit. Notably, APTVIran has threatened to create a 'zombie' network from infected devices, amplifying concerns of largescale disruption. Their actions are framed as retaliation against Israeli military operations, suggesting a likely political or state-sponsored mandate.

Key Capabilities

  • Spear-phishing campaigns
  • Ransomware deployment (ALPHV, LockBit)
  • Data exfiltration and credential harvesting

MITRE ATT&CK Tactics

Initial Access
Execution
Impact

ATT&CK Techniques

T1078.001 -ansomware: Ransomware Execution
T1566.013 - Impact scoped activity

Software / Tooling

ALPHV ransomware
LockBit ransomware

Campaigns & Victims

APTVIran has demonstrated持续 operational endurance, conducting multiple campaigns across different sectors. Their targets include not just government but also critical utilities and food security, indicating a strategic approach to maximize impact. Past operations have involved significant data breaches and disruptive attacks, targeting Israel with potential spill-over effects in the region.

IOC Patterns

  • Network traffic anomalies indicative of lateral movement
  • Signs of ransomware infection (e.g., encrypted files)
  • Unexplained system downtime or service disruption

Recommended Actions

  • Enhance network monitoring for signs of persistent threats
  • Implement robust access controls and multi-factor authentication
  • Conduct regular security audits and patch management

Suggested Tags

APT
Ransomware
Critical Infrastructure
Geopolitical Espionage

Confidence Assessment

Confidence in APTVIran's existence and general activity is high due to claimed operations and data leaks. However, specific details on their TTPs and affiliations remain speculative without further intelligence.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 Filename 2

References

  1. unit42.paloaltonetworks.com — Cited by web research for: UNC1549
  2. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  3. attack.mitre.org — Cited by web research for: T1102
  4. www.group-ib.com — Cited by web research for: T1059.001
  5. www.proofpoint.com — Cited by web research for: Cobalt

Intel Summary

40

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Ransomware
Financial Targeting
Healthcare Targeting
Critical Infrastructure
Government Targeting
APT
Geopolitical Espionage

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.