Apt42

Threat Actor updated 12 days ago (2024-08-26T13:18:00.037Z)
Download STIX
Preview STIX
APT42, also known as Charming Kitten and CharmingCypress, is an Iran-nexus advanced persistent threat (APT) group known for its sophisticated and persistent cyber-attack strategies. The group has recently targeted Middle East policy experts in the region, as well as in the US and Europe, using a phony webinar platform to compromise its targeted victims. This tradecraft is common among APT groups like APT42 and Phosphorus, with TAG-56 illustrating many of the known tactics, techniques, and procedures (TTPs) associated with these groups. Some operators have been known to send links directly to victims' WhatsApp or Telegram accounts, manipulating them through social engineering. In August, Google revealed that APT42 attempted to compromise the email accounts of individuals associated with the respective US Presidential campaigns via spearphishing attacks. The attackers used spoofed emails from the Institute for the Study of War (ISW) to invite the victim to a fake podcast, ultimately delivering malware named BlackSmith via a malicious GoogleDrive link. Google's research attributed Iranian campaign hacking to APT42, which operates on behalf of the Islamic Revolutionary Guard Corps Intelligence Organization. Since June 2024, Insikt Group has tracked infrastructure linked to GreenCharlie, another Iran-nexus cyber threat group with connections to Mint Sandstorm, Charming Kitten, and APT42. There has been a significant increase in cyber threat activity from GreenCharlie. APT42 has shown the ability to run numerous simultaneous phishing campaigns, particularly focused on Israel and the U.S. In the last six months, Google successfully disrupted the use of Google Sites in over 50 campaigns carried out by APT42. The group uses social engineering tactics to trick targets into setting up video meetings, leading to phishing pages.
Description last updated: 2024-08-26T13:16:14.949Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Charming Kitten
4
Charming Kitten, also known as APT42, Storm-2035, Damselfly, Mint Sandstorm, TA453, and Yellow Garuda, is an Iranian threat actor group that has been linked to various cyber attacks. It has targeted entities in Brazil, Israel, and the United Arab Emirates using a new backdoor, as revealed by securit
TA453
4
TA453, also known as Charming Kitten, APT35, APT42, Ballistic Bobcat, Phosphorus, and Ajax Security Team, is a threat actor linked to the Iranian government. This group has been implicated in numerous cyber espionage activities targeting various entities globally. In one notable incident, researcher
Phosphorus
3
Phosphorus, also known as APT35 or Charming Kitten, is a notorious Iranian cyberespionage group linked to the Islamic Revolutionary Guard Corps (IRGC). This threat actor has been involved in a series of malicious activities, employing novel tactics and tools. A significant discovery was made by the
APT35
3
APT35, also known as the Newscaster Team, Charming Kitten, and Mint Sandstorm, is an Iranian government-sponsored cyber espionage group. The group focuses on long-term, resource-intensive operations to collect strategic intelligence. They primarily target sectors in the U.S., Western Europe, and the
Mint Sandstorm
3
Mint Sandstorm, an Advanced Persistent Threat (APT) group linked to Iran's Islamic Revolutionary Guard Corps (IRGC), has been identified as a significant cyber threat actor. This group is known for its highly skilled operators and sophisticated social engineering techniques, often lacking the typica
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Phishing
Apt
Whatsapp
Email Accounts
Google
Exploit
Microsoft
Malware
Iran
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Apt42 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Malwarebytes
8 days ago
Iranian cybercriminals are targeting WhatsApp users in spear phishing campaign | Malwarebytes
Checkpoint
12 days ago
26th August – Threat Intelligence Report - Check Point Research
InfoSecurity-magazine
18 days ago
Iran Behind Trump Campaign Hack, US Government Confirms
Recorded Future
18 days ago
GreenCharlie Infrastructure Targeting US Political Entities with Advanced Phishing and Malware
BankInfoSecurity
19 days ago
FBI Confirms Iranian Hack Targeting Trump Campaign
Securityaffairs
21 days ago
Security Affairs newsletter Round 485 by Pierluigi Paganini – INTERNATIONAL EDITION
Securityaffairs
23 days ago
Google disrupted hacking campaigns carried out by Iran-linked APT42
DARKReading
23 days ago
Google: Iran's Charming Kitten Targets US Elections, Israeli Military
InfoSecurity-magazine
23 days ago
Google Warns of Iranian Cyber-Attacks on Presidential Campaigns
BankInfoSecurity
4 months ago
New Report Exposes Iranian Hacking Group's Media Masquerade
DARKReading
7 months ago
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets
CERT-EU
8 months ago
Iranian threat group Mint Sandstorm targets high-profile Middle East researchers
CERT-EU
10 months ago
Iran’s role in Israel-Hamas war largely 'opportunistic'
CERT-EU
a year ago
Iran-linked APT TA453 targets Windows and macOS systems | IT Security News
Securityaffairs
a year ago
Iran-linked APT TA453 targets Windows and macOS systems
BankInfoSecurity
a year ago
Feds Urge Immediately Patching of Zoho and Fortinet Products
Securityaffairs
a year ago
Iran-linked Mint Sandstorm APT targeted US critical infrastructure
Recorded Future
2 years ago
Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
BankInfoSecurity
a year ago
Iranian Hackers Gain Sophistication, Microsoft Warns
CERT-EU
a year ago
Iranian Cyberspies Deployed New Backdoor to 34 Organizations