APT39 — APT Profile
APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.Also tracked as
ITG07, Chafer, Remix Kitten
Tools & malware
- apk.rana Mobile Malware
- ASPXSpy Web Shell
- Cadelspy Backdoor
- CrackMapExec Network Toolkit
- ftp Exfiltration
- MechaFlounder Backdoor
- Mimikatz Credential Harvesting
- NBTscan Network Reconnaissance
- php.antak Web Shell
- php.aspxspy Infostealer
- ps1.oilrig Backdoor
- PsExec Remote Execution
- pwdump Credential Harvesting
- Remexi Backdoor
- win.remexi Backdoor
- Windows Credential Editor Credential Harvesting
Vendor research
- Mandiant Google Threat Intelligence
- Treasury Sanctions Cyber Actors Backed by Iranian Intelligence Dept
- Department of Justice and Partner Departments and Agencies Conduct Coordinated Actions to Disrupt and Deter Iranian Malicious Cyber Activities Targeting the United States and the Broader International Community DOJ
- Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07 FBI
- 2020 Global Threat Report Crowdstrike
- Iran Ups its Traditional Cyber Espionage Tradecraft Dark Reading
- Iran-based attackers use back door threats to spy on Middle Eastern targets Symantec
- APT39: An Iranian Cyber Espionage Group Focused on Personal Information FireEye