APT42 is an Iranian state-linked cyber espionage threat actor widely associated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). It is also known as Charming Kitten, TA453, Phosphorus, Mint Sandstorm, Agent Serpens, and Educated Manticore. The group is characterized by highly targeted, relationship-driven social engineering and credential theft operations focused on intelligence collection rather than disruptive or financially motivated activity. APT42 commonly targets journalists, researchers, academics, activists, civil society organizations, non-profits, diplomats, policy experts, government-linked individuals, and political campaign personnel. Reported targeting has also included defense officials, military and diplomatic organizations, and high-profile individuals connected to U.S. presidential campaigns. The group has also targeted organizations and individuals throughout Europe and Israeli government, military, and diplomatic interests. Its tradecraft centers on prolonged rapport-building over email and messaging platforms, impersonation of legitimate people, conference or interview lures, and credential-harvesting pages that mimic major cloud and webmail providers. APT42 has conducted adversary-in-the-middle style phishing and MFA bypass activity, including theft of usernames, passwords, authentication codes, session cookies, and cloud account access. Post-compromise activity has included access to email, cloud storage, calendars, contacts, mailbox synchronization, data export, and use of built-in Microsoft 365 features and other legitimate services to reduce detection. APT42 has also used custom malware, including TAMECAT, in selected operations. Reported capabilities of TAMECAT include browser credential and cookie theft, Outlook data access, screenshot capture, command execution, file discovery, and data exfiltration. The group has used PowerShell, DNS-based command-and-control patterns, HTTPS-based command and control, Base64-encoded C2 traffic, and publicly available tools alongside native platform features. It has also performed security software discovery using WMI, modified registry keys for persistence, and has been associated with persistence mechanisms mapped to boot or logon initialization and autostart execution techniques. Recent reporting indicates APT42 has incorporated generative AI into target research, persona development, translation, and phishing message refinement, improving the realism and scalability of its social engineering without fundamentally changing its core operating model. Across reporting, APT42 is consistently assessed as an espionage-focused Iranian threat actor specializing in high-trust social engineering, credential theft, cloud collection, and stealthy post-compromise access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
164 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting AI-assisted phishing and intelligence-collection operations against U.S. organizations, using rapport-building social engineering and evolving delivery, persistence, and recovery methods.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Conducting cyber espionage via relationship-based phishing, credential theft, and malware delivery using AI-assisted target research and social engineering, including deployment of TAMECAT against high-value government and defense-related targets.
IRGC-linked Iranian group conducting credential theft through social engineering and MFA bypass without malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.