An Iran-sponsored threat group known for long-term intelligence collection targeting military, diplomatic, and energy sectors.
Analyst brief
APT35, sponsored by Iran, is a threat group conducting long-term, resource-intensive intelligence collection operations since at least 2014. It primarily targets US and Middle Eastern military, diplomatic, government, media, energy, defense, and telecommunications sectors. Key TTPs include credential dumping (LSASS Memory, Mimikatz), PowerShell-based execution (CharmPower, PowerLess), RDP lateral movement, keylogging, screen capture, and exfiltration over web services. Defenders should prioritize patching public-facing applications, enforcing strong multi-factor authentication, monitoring PowerShell activity, and restricting access to LSASS memory.
APT35
Newscaster TeamMagic HoundG0059
unknown
FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government that conducts long term, resource-intensive operations to collect strategic intelligence. APT35 typically targets U.S. and the Middle Eastern military, diplomatic and government personnel, organizations in the media, energy and defense industrial base (DIB), and engineering, business services and telecommunications sectors.