APT42
MITRE ATT&CK: G1044 View on attack.mitre.org
Aliases: UNC788, CALANQUE, APT42
- First seen
- 2015-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-05-10 05:17:50
- Profile updated
- 2026-07-07 11:52:15
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:sa country_code:ae country_code:qa
Context
APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools. APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to APT42 (G1044). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | ApkViruses.zip | 2026-05-10 | 1 |
Detection coverage
- 541 Sigma rules
Malware & tools used
- Security Software Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Indicator Removal (attack-pattern)
- Input Capture (attack-pattern)
- Domains (attack-pattern)
- Standard Encoding (attack-pattern)
- Data from Cloud Storage (attack-pattern)
- Visual Basic (attack-pattern)
- Screen Capture (attack-pattern)
- Impersonation (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Local Account (attack-pattern)
- Email Accounts (attack-pattern)
- Scheduled Task (attack-pattern)
- Query Public AI Services (attack-pattern)
- Clear Mailbox Data (attack-pattern)
- Keylogging (attack-pattern)
- Web Service (attack-pattern)
- System Information Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Virtual Private Server (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Upload Malware (attack-pattern)
Related threat objects
- TA453 (threat-actor)
- APT35 (threat-actor)
- Charming Kitten (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
- Mandiant — Apt42 Charms Cons Compromises (report)
- MITRE ATT&CK — G1044 (report)
- cloud.google.com — Untangling Iran Apt42 Operations (report)
- services.google.com — Apt42 Crooked Charms Cons And Compromises (report)