VINETHORN is a malware payload used by APT42, an Iranian state-sponsored cyberespionage group targeting individuals and organizations of strategic interest to Iran. It masquerades as a VPN application, using an apparently legitimate software identity to conceal its malicious nature and encourage installation. APT42 has staged VINETHORN on infrastructure also used for command-and-control operations. Its documented deployment is associated with the group’s espionage and surveillance activity; specific payload functionality and targeted operating systems are not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tools used by APT42: CHAIRSMACK, GHAMBAR, POWERPOST, BROKEYOLK, MAGICDROP, PINEFLOWER, TABBYCAT, TAMECAT, VBREVSHELL, VINETHORN, DOSTEALER
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple Iran-nexus APT groups are described as using spear-phishing: e.g., Charming Kitten uses “spear-phishing with fake personas and compromised emails… phishing via benign PDFs for credential harvesting”; several others use “spear-phishing with malicious documents/attachments/links.”
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in spear-phishing-led espionage and dissident monitoring operations.
Malware delivered via spear-phishing by Imperial Kitten (APT42) for espionage and surveillance.
Named as a tool used by APT42; its functionality is not described.
A payload staged by APT42 that masquerades as a VPN application and is supported by actor infrastructure used for command-and-control (C2).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.