APT42

MITRE ATT&CK: G1044 View on attack.mitre.org

Aliases: UNC788, CALANQUE, APT42

First seen
2015-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
1 (1 malicious)
Last IoC activity
2026-05-10 05:17:50
Profile updated
2026-07-07 11:52:15

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:sa country_code:ae country_code:qa

Context

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools. APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to APT42 (G1044). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample ApkViruses.zip 2026-05-10 1

Detection coverage

  • 541 Sigma rules

Malware & tools used

  • Security Software Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Input Capture (attack-pattern)
  • Domains (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Data from Cloud Storage (attack-pattern)
  • Visual Basic (attack-pattern)
  • Screen Capture (attack-pattern)
  • Impersonation (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Local Account (attack-pattern)
  • Email Accounts (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Query Public AI Services (attack-pattern)
  • Clear Mailbox Data (attack-pattern)
  • Keylogging (attack-pattern)
  • Web Service (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Upload Malware (attack-pattern)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • services.google.com — Tool Of First Resort Israel Hamas War Cyber (report)
  • Mandiant — Apt42 Charms Cons Compromises (report)
  • MITRE ATT&CK — G1044 (report)
  • cloud.google.com — Untangling Iran Apt42 Operations (report)
  • services.google.com — Apt42 Crooked Charms Cons And Compromises (report)

External references