TAG APT42

Google Threat Analysis Group. (2024, August 14). Iranian backed group steps up phishing campaigns against Israel, U.S.. Retrieved October 9, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1102
Web Service
GroupAPT42

APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.

T1566.002
Spearphishing Link
GroupAPT42

APT42 has sent spearphishing emails containing malicious links.

T1583.001
Domains
GroupAPT42

APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations.

T1585.002
Email Accounts
GroupAPT42

APT42 has created email accounts to use in spearphishing operations.

T1684.001
Impersonation
GroupAPT42

APT42 has impersonated legitimate people in phishing emails to gain credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.