APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents and Government Targets
A threat profile published by SOCRadar details APT42 — also tracked as Crooked Charms and TA453 — an Iranian cyber espionage group affiliated with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO) that has conducted at least 30 confirmed operations since 2015. The group's signature is its sophisticated social engineering: multi-persona impersonation email threads, credential-harvesting login page clones, and Android surveillance malware deployed against Iranian dissidents and opponents of the regime.
Three Operational Pillars
APT42 structures its operations around three core capabilities:
- Credential Harvesting: Spear-phishing campaigns targeting Multi-Factor Authentication codes via cloned login pages impersonating Google, Yahoo!, and OneDrive. In February 2021, Mandiant observed the group targeting a senior Israeli government official's email credentials through a fake Gmail login page. Once MFA codes are stolen, APT42 registers its own authenticator to eliminate the MFA requirement entirely for subsequent access.
- Surveillance Operations: Android malware — most notably PINEFLOWER — deployed against Iran-based individuals linked to universities, reformist political groups, and human rights activists. PINEFLOWER exfiltrates recorded calls, audio recordings, images, and SMS inboxes, and collects location data, Wi-Fi, Bluetooth, and mobile connectivity states. Mandiant observed active PINEFLOWER campaigns between June and August 2022.
- Malware Deployment: Custom lightweight backdoors for broader collection objectives, including POWERPOST (a March 2022 reconnaissance tool that collects system information and local account names), GHAMBAR (a C# RAT using SOAP API over HTTP for keylogging, screen capture, file operations, and shell commands), and BROKEYOLK (a .NET downloader that fetches and executes payloads from hardcoded C2 servers via SOAP API).
Multi-Persona Impersonation: A Novel Phishing Technique
APT42's most distinctive social engineering innovation is the Multi-Persona Impersonation (MPI) technique. The group creates multiple fake journalist or researcher profiles and constructs realistic-looking email threads around a topical subject, then introduces the real target into the conversation. After building rapport over multiple exchanges, one of the fake personas sends a link to a spoofed Google Drive or OneDrive page — either to harvest credentials or deliver a malicious file. The technique exploits the implicit trust of pre-established conversational context rather than cold phishing, significantly increasing success rates against security-aware targets.
Targeting: Opponents of the Iranian Regime Across 15+ Countries
Unlike APT35, which focuses on military and government entities in Western and Middle Eastern countries, APT42 specifically targets individuals and organizations opposed to or scrutinized by the Iranian government: civil society groups, NGOs, human rights activists, reformist political organizations, media, academia, healthcare, and pharmaceuticals. Operations have been observed in more than 15 countries including the United States, Germany, the United Kingdom, and Australia. The July 2022 cyberattack against the Albanian government represents the group's most significant publicly disclosed state-level operation.
Cluster Relationships: APT35, Nemesis Kitten, and TAG-56
While some sources conflate APT42 with APT35, Mandiant tracks them as distinct IRGC-affiliated intrusion sets with different targeting patterns and TTPs. APT42 also overlaps with Nemesis Kitten (UNC2448/DEV-0270) — a ransomware-focused Iranian actor — though Mandiant assesses no direct technical relationship, only shared IRGC-IO affiliation. The group further overlaps with TAG-56, documented by Recorded Future in November 2022, through shared use of fake registration pages and infrastructure previously associated with the Phosphorus cluster, including the domains mailer-daemon[.]org and mailerdaemon[.]me.
Full Malware Arsenal
APT42's documented toolset spans BROKEYOLK, CHAIRSMACK, DOSTEALER, GHAMBAR, MAGICDROP, PINEFLOWER, POWERPOST, SILENTUPLOADER, TABBYCAT, TAMECAT, VBREVSHELL, and VINETHORN — a breadth that reflects both the group's longevity and its capacity to develop purpose-built tools across credential theft, surveillance, and remote access mission sets.