Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: ITG07, Chafer, Remix Kitten, Cadelle, APT39, COBALT HICKMAN, G0087, Radio Serpens, TA454, Burgundy Sandstorm, CINDER ION

Description

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.(Citation: FireEye APT39 Jan 2019)(Citation: Symantec Chafer Dec 2015)(Citation: FBI FLASH APT39 September 2020)(Citation: Dept. of Treasury Iran Sanctions September 2020)(Citation: DOJ Iran Indictments September 2020)

Goals & Targeting

Targeted Sectors

Energy
Critical infrastructure
Transportation

AI Analysis

· 2 weeks ago

Executive Summary

APT39, also known as Chafer, is a cyber espionage group sponsored by the Iranian Ministry of Intelligence and Security (MOIS), primarily targeting the travel, hospitality, academic, and telecommunications industries across the globe. The group's primary motivation is espionage, and they have been active since at least 2014. APT39's activities pose a significant threat to organizations and individuals considered a threat by the MOIS.

Goals & Targeting

APT39's strategic objectives are centered around gathering intelligence on individuals and entities that are considered a threat to the MOIS. The group primarily targets the travel, hospitality, academic, and telecommunications industries, as these sectors often provide valuable information on potential security risks. APT39's typical victims include individuals and organizations that are involved in activities that are deemed a threat to the Iranian government, such as dissidents, activists, and journalists.

Enhanced Description

The group's motivations and objectives are closely tied to the interests of the MOIS, which seeks to gather intelligence on individuals and entities that may pose a threat to the Iranian government. APT39's activities are often focused on tracking and monitoring the activities of these individuals and entities, with the goal of identifying potential security risks and mitigating them. The group's operations are often clandestine in nature, with APT39 using various techniques to conceal their activities and maintain operational security.

Key Capabilities

  • Social engineering
  • Malware development and deployment
  • Network exploitation
  • Data exfiltration
  • Encryption and decryption

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1005
T1204

Software / Tooling

Custom malware
Off-the-shelf malware
Social engineering tools
Network exploitation tools

Campaigns & Victims

APT39 has been observed conducting campaigns that involve spear-phishing, social engineering, and exploitation of publicly available information. The group's operational tempo is often characterized by a high degree of persistence and stealth, with APT39 using various techniques to maintain access to compromised networks and systems. Notable past operations include the targeting of the travel, hospitality, and telecommunications industries, as well as the use of fake social media profiles and other social engineering tactics to gather intelligence.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Use of encryption and decryption tools

Recommended Actions

  • Implement robust email filtering and sandboxing solutions
  • Conduct regular security awareness training for employees
  • Implement a robust incident response plan
  • Use threat intelligence to inform security decisions

Suggested Tags

APT
espionage
Iran
cyber threat

Confidence Assessment

The confidence level in the available data on APT39 is moderate to high, based on the large amount of publicly available information and research on the group's activities. However, there may be some gaps in the data, particularly with regards to the group's current TTPs and operational tempo. Further research and analysis are needed to fully understand the scope and nature of APT39's activities.

ATT&CK Techniques

Collection
7 techniques
Command & Control
6 techniques
Discovery
6 techniques
Execution
9 techniques
Stealth
7 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Crowdstrike GTR2020 Mar 2020 — Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.
  2. Dept. of Treasury Iran Sanctions September 2020 — Dept. of Treasury. (2020, September 17). Treasury Sanctions Cyber Actors Backed by Iranian Intelligence. Retrieved December 10, 2020.
  3. DOJ Iran Indictments September 2020 — DOJ. (2020, September 17). Department of Justice and Partner Departments and Agencies Conduct Coordinated Actions to Disrupt and Deter Iranian Malicious Cyber Activities Targeting the United States and the Broader International Community. Retrieved December 10, 2020.
  4. FBI FLASH APT39 September 2020 — FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020.
  5. FireEye APT39 Jan 2019 — Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.
  6. Dark Reading APT39 JAN 2019 — Higgins, K. (2019, January 30). Iran Ups its Traditional Cyber Espionage Tradecraft. Retrieved May 22, 2020.
  7. Symantec Chafer Dec 2015 — Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

Intel Summary

53

Techniques

18

Tools

0

Campaigns

0

IOCs

0

Observed Data

13

Tactics

Tags

APT
Healthcare Targeting
Government Targeting

Details

MITRE ID
G0087
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--44e43fad-ffcb-4210-abcf-eaaed9735f80
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.