Also known as: ITG07, Chafer, Remix Kitten, Cadelle, APT39, COBALT HICKMAN, G0087, Radio Serpens, TA454, Burgundy Sandstorm, CINDER ION
APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.(Citation: FireEye APT39 Jan 2019)(Citation: Symantec Chafer Dec 2015)(Citation: FBI FLASH APT39 September 2020)(Citation: Dept. of Treasury Iran Sanctions September 2020)(Citation: DOJ Iran Indictments September 2020)
Targeted Sectors
Executive Summary
APT39, also known as Chafer, is a cyber espionage group sponsored by the Iranian Ministry of Intelligence and Security (MOIS), primarily targeting the travel, hospitality, academic, and telecommunications industries across the globe. The group's primary motivation is espionage, and they have been active since at least 2014. APT39's activities pose a significant threat to organizations and individuals considered a threat by the MOIS.
Goals & Targeting
APT39's strategic objectives are centered around gathering intelligence on individuals and entities that are considered a threat to the MOIS. The group primarily targets the travel, hospitality, academic, and telecommunications industries, as these sectors often provide valuable information on potential security risks. APT39's typical victims include individuals and organizations that are involved in activities that are deemed a threat to the Iranian government, such as dissidents, activists, and journalists.
Enhanced Description
The group's motivations and objectives are closely tied to the interests of the MOIS, which seeks to gather intelligence on individuals and entities that may pose a threat to the Iranian government. APT39's activities are often focused on tracking and monitoring the activities of these individuals and entities, with the goal of identifying potential security risks and mitigating them. The group's operations are often clandestine in nature, with APT39 using various techniques to conceal their activities and maintain operational security.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT39 has been observed conducting campaigns that involve spear-phishing, social engineering, and exploitation of publicly available information. The group's operational tempo is often characterized by a high degree of persistence and stealth, with APT39 using various techniques to maintain access to compromised networks and systems. Notable past operations include the targeting of the travel, hospitality, and telecommunications industries, as well as the use of fake social media profiles and other social engineering tactics to gather intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on APT39 is moderate to high, based on the large amount of publicly available information and research on the group's activities. However, there may be some gaps in the data, particularly with regards to the group's current TTPs and operational tempo. Further research and analysis are needed to fully understand the scope and nature of APT39's activities.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
53
Techniques
18
Tools
0
Campaigns
0
IOCs
0
Observed Data
13
Tactics