APT42
APT42 is an Iran-nexus threat actor suspected to operate on behalf of Iran’s Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). Known aliases in the provided content include Educated Manticore, Charming Kitten, and Microsoft’s Mint Sandstorm. The content describes APT42 as one of the primary Iranian espionage actors, historically focused on intelligence collection and surveillance operations against individuals and organizations of interest to the Iranian government. Reported targeting in the provided content includes journalists, researchers, dissidents, political consultants, civil society and non-profit organizations, government entities throughout Europe, both U.S. presidential campaigns in 2024, and Israeli military, government, diplomatic, journalist, and academic targets. The content also states that APT42 has targeted both Democratic and Republican campaign personnel and previously targeted both sides in U.S. elections for intelligence collection. APT42 is described as relying heavily on social engineering, impersonation, and credential harvesting. The content states that it has impersonated legitimate people in phishing emails to gain credentials and commonly begins with legitimate contact over email, WhatsApp, or Telegram, builds trust over time, and then sends phishing links. Reported lures and impersonation themes include media and think tanks, as well as services such as Dropbox, Google Meet, YouTube, WhatsApp, Microsoft Teams, and Google Meet. The content specifically describes adversary-in-the-middle phishing for MFA interception, capture of usernames, passwords, TOTP codes, and session cookies, and in some cases a shift to MFA push bombing when token interception failed. Post-compromise, the content states that APT42 has used built-in Microsoft 365 and cloud features and publicly available tools to avoid detection, including registering its own MFA authenticator, reading Outlook mail, and downloading files from OneDrive and SharePoint. The content also notes that APT42 leaves minimal endpoint artifacts and is often more visible in cloud and proxy logs. Additional TTPs directly mentioned in the content include PowerShell execution, Base64-encoded C2 traffic, NICECURL command-and-control over HTTPS, use of anonymized infrastructure and VPSs, scheduled tasks for persistence, registry modification for persistence, malware such as GHAMBAR and POWERPOST to collect system information, and masquerading the VINETHORN payload as a VPN application. The content also notes a weak overlap between APT42 and a separate Iran-linked counterintelligence campaign, while stating no observed relationship between that activity and previously reported U.S. election-related targeting.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
66 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian cyber-espionage group focused on targeting specific individuals such as journalists, researchers, dissidents, and political consultants. The group uses social engineering, credential harvesting, adversary-in-the-middle phishing, MFA interception, session cookie theft, and then operates inside cloud services such as Microsoft 365 for email and document collection without deploying malware on endpoints.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Uses social engineering priming to build trust with victims before delivering malicious files.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.