APT42

G1044

Threat group.View on attack.mitre.org

About this group

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools.

APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.

Techniques used32

Procedure examples32

TechniqueProcedure example
T1016
System Network Configuration Discovery

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information.

T1036.005
Match Legitimate Resource Name or Location

APT42 has masqueraded the VINETHORN payload as a VPN application.

T1047
Windows Management Instrumentation

APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1053.005
Scheduled Task

APT42 has used scheduled tasks for persistence.

T1056
Input Capture

APT42 has used credential harvesting websites.

T1056.001
Keylogging

APT42 has used custom malware to log keystrokes.

T1059.001
PowerShell

APT42 has downloaded and executed PowerShell payloads.

T1059.005
Visual Basic

APT42 has used a VBScript to query anti-virus products.

T1070
Indicator Removal

APT42 has cleared Chrome browser history.

T1070.008
Clear Mailbox Data

APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks.

T1071.001
Web Protocols

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1082
System Information Discovery

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect system information.

T1087.001
Local Account

APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine.

T1102
Web Service

APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.

T1111
Multi-Factor Authentication Interception

APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens.

View all 32 procedure examples

Software2

Campaigns0

None recorded.

References2

  1. Mandiant APT42-charms Open source
    Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.
  2. Mandiant APT42-untangling Open source
    Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.