NEW: Group Profiler — instant APT intel lookup. Try it →

APT42

G1044 Iran Espionage MITRE ATT&CK →

Overview

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools. APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.

Naming & attribution

APT42 is tracked under 1 names across the industry. It uses 32 documented ATT&CK techniques — more than 69% of the 174 groups tracked here. Activity attributed since at least 2015.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1547 Boot or Logon Autostart Execution — used by 1 of 174 groups
  • T1070.008 Clear Mailbox Data — used by 2 of 174 groups
  • T1682 Query Public AI Services — used by 2 of 174 groups
  • T1056 Input Capture — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TA2541 — 12 shared techniques (25% overlap)
  • OilRig Iran — 18 shared techniques (20% overlap)
  • MuddyWater Iran — 16 shared techniques (19% overlap)
  • APT-C-36 — 11 shared techniques (19% overlap)
  • FIN8 — 11 shared techniques (19% overlap)
  • HEXANE — 11 shared techniques (19% overlap)

Targets

Civil society · Defense · Education · Energy · Finance · Government · Healthcare · Legal · Manufacturing · Media · Military · NGOs · Pharmaceuticals

Regions

Australia · Europe · Israel · Middle East · United States

TTPs — 32 techniques across 11 tactics

Reconnaissance

Resource Development

Initial Access

Execution

Defense Impairment

Collection

Command and Control

Tools & malware (2)

NICECURL · TAMECAT

Reporting (1)