APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents

APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents and Government Targets

A threat profile published by SOCRadar details APT42 — also tracked as Crooked Charms and TA453 — an Iranian cyber espionage group affiliated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO) that has conducted at least 30 confirmed operations since 2015. The group's signature is its sophisticated social engineering: multi-persona impersonation email threads, credential-harvesting login page clones, and Android surveillance malware deployed against Iranian dissidents and opponents of the regime.

Three Operational Pillars

APT42 structures its operations around three core capabilities:

Multi-Persona Impersonation: A Novel Phishing Technique

APT42's most distinctive social engineering innovation is the Multi-Persona Impersonation (MPI) technique. The group creates multiple fake journalist or researcher profiles and constructs realistic-looking email threads around a topical subject, then introduces the real target into the conversation. After building rapport over multiple exchanges, one of the fake personas sends a link to a spoofed Google Drive or OneDrive page — either to harvest credentials or deliver a malicious file. The technique exploits the implicit trust of pre-established conversational context rather than cold phishing, significantly increasing success rates against security-aware targets.

Targeting: Opponents of the Iranian Regime Across 15+ Countries

Unlike APT35, which focuses on military and government entities in Western and Middle Eastern countries, APT42 specifically targets individuals and organizations opposed to or scrutinized by the Iranian government: civil society groups, NGOs, human rights activists, reformist political organizations, media, academia, healthcare, and pharmaceuticals. Operations have been observed in more than 15 countries including the United States, Germany, the United Kingdom, and Australia. The July 2022 cyberattack against the Albanian government represents the group's most significant publicly disclosed state-level operation.

Cluster Relationships: APT35, Nemesis Kitten, and TAG-56

While some sources conflate APT42 with APT35, Mandiant tracks them as distinct IRGC-affiliated intrusion sets with different targeting patterns and TTPs. APT42 also overlaps with Nemesis Kitten (UNC2448/DEV-0270) — a ransomware-focused Iranian actor — though Mandiant assesses no direct technical relationship, only shared IRGC-IO affiliation. The group further overlaps with TAG-56, documented by Recorded Future in November 2022, through shared use of fake registration pages and infrastructure previously associated with the Phosphorus cluster, including the domains mailer-daemon[.]org and mailerdaemon[.]me.

Full Malware Arsenal

APT42's documented toolset spans BROKEYOLK, CHAIRSMACK, DOSTEALER, GHAMBAR, MAGICDROP, PINEFLOWER, POWERPOST, SILENTUPLOADER, TABBYCAT, TAMECAT, VBREVSHELL, and VINETHORN — a breadth that reflects both the group's longevity and its capacity to develop purpose-built tools across credential theft, surveillance, and remote access mission sets.

Read the full analysis on IntelFusions