APT42 — APT Profile
APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools. APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
UNC788, CALANQUE, CALANQUE ION
IntelFusions coverage (2)
- State hackers now log in instead of dropping malware 2026-08-20 · Nation-State
- APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents 2026-02-16 · Nation-State
Tools & malware
Vendor research
- Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises Mandiant
- Uncharmed: Untangling Iran's APT42 Operations Mandiant
Countries linked to this actor
- United Kingdom targets
- Israel targets