APT42
Iranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against individuals and organizations of strategic interest to the Iranian government.
APT42 is an Iranian state-sponsored cyber espionage group known for persistent surveillance and intelligence collection against strategic targets.
APT42 is an Iranian state-sponsored cyber espionage group conducting intelligence collection and surveillance against targets of strategic interest. The group primarily targets government, defense, energy, healthcare, education, and financial sectors in Australia, Europe, the United States, the Middle East, and Israel. Key TTPs include spearphishing with malicious links, execution via PowerShell and Visual Basic, stealing web session cookies, collecting data from cloud storage, and deploying NICECURL and TAMECAT malware. Defenders should focus on email security, monitoring for unusual queries to public AI services, protecting session cookies, and inspecting boot or logon autostart execution points.
Iranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against individuals and organizations of strategic interest to the Iranian government.
Monitor unusual queries against AI services and log suspicious activity.
Monitor domain and email registrations for newly registered domains and email accounts.
Implement anti-spearphishing controls to identify suspicious email links.
Monitor and log PowerShell and Visual Basic executions to identify suspicious scripts.
Monitor system configurations for autostart execution and log suspicious changes.
Monitor resource names and locations to identify suspicious names and locations regardless of legitimacy.
Harden web browser security to prevent web session cookie theft.
Monitor system queries to identify network configuration and security software discovery.
Implement input capture and cloud storage security to prevent user input and cloud stored data collection.
Implement network monitoring to identify suspicious encoding schemes in network traffic.
Monitor Registry changes to identify and prevent suspicious modifications.
APT42 primarily targets government, defense, energy, healthcare, education, and financial sectors in Australia, Europe, the United States, the Middle East, and Israel.
The group's key TTPs include spearphishing with malicious links, execution via PowerShell and Visual Basic, stealing web session cookies, collecting data from cloud storage, and deploying NICECURL and TAMECAT malware.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.