APT39

G0087

Threat group.View on attack.mitre.org

About this group

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.

Techniques used53

Procedure examples53

TechniqueProcedure example
T1003
OS Credential Dumping

APT39 has used different versions of Mimikatz to obtain credentials.

T1003.001
LSASS Memory

APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials.

T1005
Data from Local System

APT39 has used various tools to steal files from the compromised host.

T1012
Query Registry

APT39 has used various strains of malware to query the Registry.

T1018
Remote System Discovery

APT39 has used NBTscan and custom tools to discover remote systems.

T1021.001
Remote Desktop Protocol

APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions.

T1021.002
SMB/Windows Admin Shares

APT39 has used SMB for lateral movement.

T1021.004
SSH

APT39 used secure shell (SSH) to move laterally among their targets.

T1027.002
Software Packing

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

T1027.013
Encrypted/Encoded File

APT39 has used malware to drop encrypted CAB files.

T1033
System Owner/User Discovery

APT39 used Remexi to collect usernames from the system.

T1036.005
Match Legitimate Resource Name or Location

APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.

T1041
Exfiltration Over C2 Channel

APT39 has exfiltrated stolen victim data through C2 communications.

T1046
Network Service Discovery

APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning.

T1053.005
Scheduled Task

APT39 has created scheduled tasks for persistence.

View all 53 procedure examples

Software11

Campaigns0

None recorded.

References5

  1. DOJ Iran Indictments September 2020 Open source
    DOJ. (2020, September 17). Department of Justice and Partner Departments and Agencies Conduct Coordinated Actions to Disrupt and Deter Iranian Malicious Cyber Activities Targeting the United States and the Broader International Community. Retrieved December 10, 2020.
  2. Dept. of Treasury Iran Sanctions September 2020 Open source
    Dept. of Treasury. (2020, September 17). Treasury Sanctions Cyber Actors Backed by Iranian Intelligence. Retrieved December 10, 2020.
  3. FBI FLASH APT39 September 2020 Open source
    FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020.
  4. FireEye APT39 Jan 2019 Open source
    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.
  5. Symantec Chafer Dec 2015 Open source
    Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.