Also known as: Chafer, APT39, OilRig, Helix Kitten, MuddyWater, tracked as, Elfin, Refined Kitten, APT33, APT34, Hazel Sandstorm, Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Earth Simnavaz, is a sophisticated, UNC1549, Smoke Sandstorm, Iranian Dream Job, Advanced Persistent Threat 39, Cadelspy, Remexi, ITG07
APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of government ministries, hospitals, universities, and financial institutions as retaliation for Israeli military operations. The group has leaked over 350,000 Israeli government login credentials and approximately 300 internal databases, while also threatening to create a 'zombie' network from infected devices. They have reportedly deployed ransomware strains such as ALPHV and LockBit as part of their offensive toolkit. Additionally, APTIran has made unverified claims of compromising Israeli water control systems and the state-owned food security agency Jordan Silos and Supply General Co.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APTVIran emerges as a significant cyber threat targeting Israeli critical infrastructure. The group claims to be retaliating against Israeli military operations through sophisticated cyberattacks, including ransomware deployment. Their activities highlight a growing trend of state-sponsored or politically motivated cyberattacks, posing substantial risks to national security and public services.
Goals & Targeting
APTVIran's primary objectives involve disrupting operations in critical sectors and creating public panic through threats of widespread infrastructure control. They target Israel, possibly due to geopolitical tensions or specific military-related grievances, focusing on entities that could cause maximum disruption and fear.
Enhanced Description
APTVIran is an active threat actor claiming responsibility for extensive cyberattacks on Israeli targets, notably critical infrastructure sectors such as government ministries, healthcare, education, and finance. The group has achieved substantial impact by infiltrating systems to leak sensitive information and deploy ransomware, including ALPHV and LockBit. Notably, APTVIran has threatened to create a 'zombie' network from infected devices, amplifying concerns of largescale disruption. Their actions are framed as retaliation against Israeli military operations, suggesting a likely political or state-sponsored mandate.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APTVIran has demonstrated持续 operational endurance, conducting multiple campaigns across different sectors. Their targets include not just government but also critical utilities and food security, indicating a strategic approach to maximize impact. Past operations have involved significant data breaches and disruptive attacks, targeting Israel with potential spill-over effects in the region.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in APTVIran's existence and general activity is high due to claimed operations and data leaks. However, specific details on their TTPs and affiliations remain speculative without further intelligence.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics