APT39
MITRE ATT&CK: G0087 View on attack.mitre.org
Aliases: ITG07, Chafer, Remix Kitten, REMIX KITTEN, COBALT HICKMAN, Radio Serpens, TA454, Burgundy Sandstorm, APT39, Cadelle
- First seen
- 2014-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-06 12:56:18
- Profile updated
- 2026-07-07 11:49:31
Targeted industries: retail-and-hospitality education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:ir country_code:as country_code:af country_code:eu country_code:us
Context
APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.
Detection coverage
- 12 YARA rules
- 988 Sigma rules
Malware & tools used
- Network Service Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- External Proxy (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Keylogging (attack-pattern)
- Data from Local System (attack-pattern)
- PowerShell (attack-pattern)
- Clipboard Data (attack-pattern)
- OS Credential Dumping (attack-pattern)
- Code Signing Policy Modification (attack-pattern)
- AppInit DLLs (attack-pattern)
- Shortcut Modification (attack-pattern)
- Network Share Discovery (attack-pattern)
- Service Execution (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Tool (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Software Packing (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Malicious File (attack-pattern)
- Scheduled Task (attack-pattern)
- File Deletion (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Archive via Utility (attack-pattern)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- Broadcom/Symantec — Iran Based Attackers Use Back Door Threats Spy Middle Eastern Targets (report)
- Mandiant — Apt39 Iranian Cyber Espionage Group Focused On Personal Information (report)
- Broadcom/Symantec — Chafer Latest Attacks Reveal Heightened Ambitions (report)
- Palo Alto Unit 42 — New Python Based Payload Mechaflounder Used By Chafer (report)
- Kaspersky — 89538 (report)
- MITRE ATT&CK — G0087 (report)
- secureworks.com — Cobalt Hickman (report)
- Palo Alto Unit 42 — Radioserpens (report)
- securityintelligence.com — Observations Of Itg07 Cyber Operations (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- home.treasury.gov — Sm1127 (report)
- darkreading.com — 1333764 (report)
- iranwatch.org — Public Intelligence Alert (report)
- justice.gov — Department Justice And Partner Departments And Agencies Conduct Coordinated Actions Disrupt (report)
External references
- mitre-attack — G0087
- Remix Kitten
- ITG07
- APT39
- Chafer
- Crowdstrike GTR2020 Mar 2020
- Dept. of Treasury Iran Sanctions September 2020
- DOJ Iran Indictments September 2020
- FBI FLASH APT39 September 2020
- FireEye APT39 Jan 2019
- Dark Reading APT39 JAN 2019
- Symantec Chafer Dec 2015
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy