AppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad. This spyware is designed to silently infiltrate victims' devices and gather personal and corporate information, including private communications and photos. The group has been distributing the spyware through fake apps and targeting primarily Middle Eastern enterprises.
Executive Summary
AppMilad is an Iranian hacking group known for the RatMilad spyware campaign. They target primarily Middle Eastern enterprises through fake apps, aiming to gather corporate and personal information.
Goals & Targeting
AppMilad's goals appear to be centered around the acquisition of sensitive corporate information and personal data. By targeting Middle Eastern enterprises, they may be seeking to gather intelligence relevant to political or economic interests, possibly aligned with broader Iranian espionage objectives. Their choice of fake apps as a delivery mechanism indicates an understanding of target demographics and a desire for stealthy infiltration.
Enhanced Description
AppMilad is an Iranian threat group identified as the source of the RatMilad spyware. This malware infiltrates devices covertly, targeting corporate and personal data, including communications and photos. The group's primary method involves distributing malicious software through fake apps, particularly focusing on Middle Eastern enterprises. Their activities suggest a focus on intelligence gathering, likely for espionage purposes, with an emphasis on sectors that could provide strategic or economic advantages.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
AppMilad has been observed targeting Middle Eastern businesses over several years. Their campaigns typically involve initial infection through app distribution, followed by lateral movement within networks and data exfiltration. No specific high-profile campaigns have been widely reported beyond their use of RatMilad spyware.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is medium in the accuracy of the threat actor's details due to limited available intelligence. Further clarity would help confirm specific TTPs, associated tools beyond RatMilad, and exact campaign history.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics