APT39, also tracked as Chafer, is a cyber threat actor primarily targeting the telecommunications and travel sectors in the Middle East.
Analyst brief
APT39, also tracked as Chafer, is a cyber threat actor with global targeting that is heavily concentrated in the Middle East. The group primarily targets the telecommunications sector, along with the travel industry, supporting IT firms, and the high-tech industry. Their key TTPs include Spearphishing Link for initial access, PowerShell for execution, Shortcut Modification for persistence, and the use of credential access tools like Mimikatz and pwdump, with External Proxy for C2. Defenders should focus on monitoring for phishing emails, suspicious PowerShell activity, credential dumping attempts, and unusual network discovery over RDP.
APT39
ChaferREMIX KITTENCOBALT HICKMAN
unknown
APT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a group publicly referred to as "Chafer." However, there are differences in what has been publicly reported due to the variances in how organizations track activity. APT39 primarily leverages the SEAWEED and CACHEMONEY backdoors along with a specific variant of the POWBAT backdoor. While APT39's targeting scope is global, its activities are concentrated in the Middle East. APT39 has prioritized the telecommunications sector, with additional targeting of the travel industry and IT firms that support it and the high-tech industry.