Also known as: UNC788, CALANQUE, CALANQUE ION
APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.(Citation: Mandiant APT42-charms) The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.(Citation: Mandiant APT42-charms) APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices.(Citation: Mandiant APT42-charms) Finally, APT42 exfiltrates data using native features and open-source tools.(Citation: Mandiant APT42-untangling) APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.
Targeted Sectors
Executive Summary
APT42, an Iranian-sponsored cyber threat group, engages in cyber espionage targeting various sectors globally. Known for spearphishing campaigns and PINEFLOWER malware, APT42 compromises systems to gather sensitive information. Their activities raise concerns due to potential state-backed objectives.
Goals & Targeting
APT42's strategic objectives align with gathering sensitive information for political or economic gain, likely supporting Iranian interests. Their targeting of various sectors suggests a goal to compromise critical infrastructure and accumulate intelligence. The focus on Middle Eastern countries underscores potential state-sponsored activities aimed at regional influence and dominance.
Enhanced Description
APT42 is a sophisticated Iranian-sponsored threat group primarily involved in cyber espionage and surveillance. Established since at least 2015, they have targeted a diverse range of industries including education, government, defense, energy, financial services, healthcare, pharmaceuticals, legal services, manufacturing, media, and non-profits, with a notable focus on the Middle East region. APT42's operations typically begin with spearphishing emails or deploying the PINEFLOWER Android malware to gain initial access. Once inside a network, they establish persistence through scheduling tasks or modifying system configurations. The group uses native features and open-source tools for data collection and exfiltration, minimizing their attack signature and avoiding detection by security systems. Their campaigns have been linked to phishing operations against Israel and the U.S., indicating region-specific targeting. Despite behavioral overlaps with Magic Hound, APT42 is considered a distinct entity.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT42's campaigns often involve long-term persistence, targeting Middle Eastern countries and various industries. Their operations against Israel and the U.S. demonstrate a shift towards global expansion beyond regional focus. Notable tactics include spearphishing emails containing malicious links or attachments, followed by deployment of malware for data collection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in APT42's Iranian sponsorship based on Mandiant reporting. Limited visibility into exact operational details and toolkits, hindering comprehensive analysis.
No observed data linked yet.
32
Techniques
2
Tools
1
Campaigns
45
IOCs
0
Observed Data
11
Tactics