Threat group.View on attack.mitre.org
APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
APT39 has used different versions of Mimikatz to obtain credentials. |
| T1003.001 LSASS Memory |
APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials. |
| T1005 Data from Local System |
APT39 has used various tools to steal files from the compromised host. |
| T1012 Query Registry |
APT39 has used various strains of malware to query the Registry. |
| T1018 Remote System Discovery |
APT39 has used NBTscan and custom tools to discover remote systems. |
| T1021.001 Remote Desktop Protocol |
APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions. |
| T1021.002 SMB/Windows Admin Shares |
APT39 has used SMB for lateral movement. |
| T1021.004 SSH |
APT39 used secure shell (SSH) to move laterally among their targets. |
| T1027.002 Software Packing |
APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| T1027.013 Encrypted/Encoded File |
APT39 has used malware to drop encrypted CAB files. |
| T1033 System Owner/User Discovery |
|
| T1036.005 Match Legitimate Resource Name or Location |
APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| T1041 Exfiltration Over C2 Channel |
APT39 has exfiltrated stolen victim data through C2 communications. |
| T1046 Network Service Discovery |
APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning. |
| T1053.005 Scheduled Task |
APT39 has created scheduled tasks for persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.