APT39

MITRE ATT&CK: G0087 View on attack.mitre.org

Aliases: ITG07, Chafer, Remix Kitten, REMIX KITTEN, COBALT HICKMAN, Radio Serpens, TA454, Burgundy Sandstorm, APT39, Cadelle

First seen
2014-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-06 12:56:18
Profile updated
2026-07-07 11:49:31

Targeted industries: retail-and-hospitality education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:ir country_code:as country_code:af country_code:eu country_code:us

Context

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.

Detection coverage

  • 12 YARA rules
  • 988 Sigma rules

Malware & tools used

  • Network Service Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • External Proxy (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Keylogging (attack-pattern)
  • Data from Local System (attack-pattern)
  • PowerShell (attack-pattern)
  • Clipboard Data (attack-pattern)
  • OS Credential Dumping (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • AppInit DLLs (attack-pattern)
  • Shortcut Modification (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Service Execution (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Tool (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Software Packing (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Malicious File (attack-pattern)
  • Scheduled Task (attack-pattern)
  • File Deletion (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Archive via Utility (attack-pattern)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • Broadcom/Symantec — Iran Based Attackers Use Back Door Threats Spy Middle Eastern Targets (report)
  • Mandiant — Apt39 Iranian Cyber Espionage Group Focused On Personal Information (report)
  • Broadcom/Symantec — Chafer Latest Attacks Reveal Heightened Ambitions (report)
  • Palo Alto Unit 42 — New Python Based Payload Mechaflounder Used By Chafer (report)
  • Kaspersky — 89538 (report)
  • MITRE ATT&CK — G0087 (report)
  • secureworks.com — Cobalt Hickman (report)
  • Palo Alto Unit 42 — Radioserpens (report)
  • securityintelligence.com — Observations Of Itg07 Cyber Operations (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • home.treasury.gov — Sm1127 (report)
  • darkreading.com — 1333764 (report)
  • iranwatch.org — Public Intelligence Alert (report)
  • justice.gov — Department Justice And Partner Departments And Agencies Conduct Coordinated Actions Disrupt (report)

External references