Threat group.View on attack.mitre.org
APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools.
APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information. |
| T1036.005 Match Legitimate Resource Name or Location |
APT42 has masqueraded the VINETHORN payload as a VPN application. |
| T1047 Windows Management Instrumentation |
APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1053.005 Scheduled Task |
APT42 has used scheduled tasks for persistence. |
| T1056 Input Capture |
APT42 has used credential harvesting websites. |
| T1056.001 Keylogging |
APT42 has used custom malware to log keystrokes. |
| T1059.001 PowerShell |
APT42 has downloaded and executed PowerShell payloads. |
| T1059.005 Visual Basic |
APT42 has used a VBScript to query anti-virus products. |
| T1070 Indicator Removal |
APT42 has cleared Chrome browser history. |
| T1070.008 Clear Mailbox Data |
APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks. |
| T1071.001 Web Protocols |
APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1082 System Information Discovery |
APT42 has used malware, such as GHAMBAR and POWERPOST, to collect system information. |
| T1087.001 Local Account |
APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine. |
| T1102 Web Service |
APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations. |
| T1111 Multi-Factor Authentication Interception |
APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.