Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: UNC788, CALANQUE, CALANQUE ION

Description

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.(Citation: Mandiant APT42-charms) The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.(Citation: Mandiant APT42-charms) APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices.(Citation: Mandiant APT42-charms) Finally, APT42 exfiltrates data using native features and open-source tools.(Citation: Mandiant APT42-untangling) APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.

Goals & Targeting

Targeted Sectors

Education
Government
Defense
Energy
Financial services
Healthcare
Pharmaceutical
Legal services
Manufacturing
Media
Non profit

AI Analysis

· 1 week ago

Executive Summary

APT42, an Iranian-sponsored cyber threat group, engages in cyber espionage targeting various sectors globally. Known for spearphishing campaigns and PINEFLOWER malware, APT42 compromises systems to gather sensitive information. Their activities raise concerns due to potential state-backed objectives.

Goals & Targeting

APT42's strategic objectives align with gathering sensitive information for political or economic gain, likely supporting Iranian interests. Their targeting of various sectors suggests a goal to compromise critical infrastructure and accumulate intelligence. The focus on Middle Eastern countries underscores potential state-sponsored activities aimed at regional influence and dominance.

Enhanced Description

APT42 is a sophisticated Iranian-sponsored threat group primarily involved in cyber espionage and surveillance. Established since at least 2015, they have targeted a diverse range of industries including education, government, defense, energy, financial services, healthcare, pharmaceuticals, legal services, manufacturing, media, and non-profits, with a notable focus on the Middle East region. APT42's operations typically begin with spearphishing emails or deploying the PINEFLOWER Android malware to gain initial access. Once inside a network, they establish persistence through scheduling tasks or modifying system configurations. The group uses native features and open-source tools for data collection and exfiltration, minimizing their attack signature and avoiding detection by security systems. Their campaigns have been linked to phishing operations against Israel and the U.S., indicating region-specific targeting. Despite behavioral overlaps with Magic Hound, APT42 is considered a distinct entity.

Key Capabilities

  • Spearphishing campaigns
  • Deployment of PINEFLOWER Android malware
  • Use of NICECURL and TAMECAT tools for command and control
  • Exfiltration using native and open-source tools
  • Establishing persistence through scheduled tasks and registry modifications

MITRE ATT&CK Tactics

Initial Access
Persistence
Defense Evasion
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1053.005
T1113
T1132.001
T1056.001
T1036.005
T1547
T1566.002
T1583.001
T1070.008
T1112
T1585.002
T1059.001
T1546
T1056
T1573.002
T1518.001
T1071.001
T1111
T1047
T1539
T1682
T1087.001
T1530
T1082
T1608.001
T1555.003
T1016

Software / Tooling

PINEFLOWER Android Malware
NICECURL
TAMECAT

Campaigns & Victims

APT42's campaigns often involve long-term persistence, targeting Middle Eastern countries and various industries. Their operations against Israel and the U.S. demonstrate a shift towards global expansion beyond regional focus. Notable tactics include spearphishing emails containing malicious links or attachments, followed by deployment of malware for data collection.

IOC Patterns

  • Spearphishing emails with malicious links or attachments
  • Deployment of PINEFLOWER Android malware on compromised devices
  • Use of domains such as accredit-navigation.online and check-pabnel-status.live
  • Exfiltration over legitimate web services
  • Hash values associated with their tools (e.g., MD5, SHA1, SHA256)

Recommended Actions

  • Monitor network traffic for malicious domains linked to APT42.
  • Implement endpoint detection solutions for PINEFLOWER malware signatures.
  • Conduct regular phishing simulations and employee training.
  • Enhance visibility into scheduled tasks and system configuration changes.
  • Apply patches and updates to mitigate known vulnerabilities.

Suggested Tags

APT
espionage
cyber_espionage
nations-Iran
Middle_East_cyber_threats
sector-Education
sector-Government
sector-Defense

Confidence Assessment

High confidence in APT42's Iranian sponsorship based on Mandiant reporting. Limited visibility into exact operational details and toolkits, hindering comprehensive analysis.

ATT&CK Techniques

Resource Development
5 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 2 SHA-256 Hash 7 SHA-1 Hash 1 MD5 Hash 1 URL 8 Domain 1

References

  1. Mandiant APT42-charms — Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.
  2. Mandiant APT42-untangling — Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.

Intel Summary

32

Techniques

2

Tools

1

Campaigns

45

IOCs

0

Observed Data

11

Tactics

Tags

APT
Phishing
espionage
cyber_espionage
nations-Iran
Middle_East_cyber_threats
sector-Education
sector-Government
sector-Defense

Details

MITRE ID
G1044
Type
Unknown
Country of Origin
I
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c0291346-defe-48d7-9542-9e074ba1bdfb
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.