APT42
[APT42](https://attack.mitre.org/groups/G1044) is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.(Citation: Mandiant APT42-charms) The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.(Citation: Mandiant APT42-charms) [APT42](https://attack.mitre.org/groups/G1044) starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices.(Citation: Mandiant APT42-charms) Finally, [APT42](https://attack.mitre.org/groups/G1044) exfiltrates data using native features and open-source tools.(Citation: Mandiant APT42-untangling) [APT42](https://attack.mitre.org/groups/G1044) activities have been linked to [Magic Hound](https://attack.mitre.org/groups/G0059) by other commercial vendors. While there are behavior and software overlaps between [Magic Hound](https://attack.mitre.org/groups/G0059) and [APT42](https://attack.mitre.org/groups/G1044), they appear to be distinct entities and are tracked as separate entities by their originating vendor.
Properties
- stix_id
- intrusion-set--c0291346-defe-48d7-9542-9e074ba1bdfb
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (33)
Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level
Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to expor
Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web bro
Adversaries may access data from cloud storage. Many IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage,
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresse
Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their op
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather
Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide cred
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new ac
Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a sys
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is don
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Ac
Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that ca
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environ
Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operat
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple w
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality m
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a clo
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specifi
Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authentic
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through info
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A to
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can in
Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows techn
Software & Tools (2)
[NICECURL](https://attack.mitre.org/software/S1192) is a VBScript-based backdoor used by [APT42](https://attack.mitre.org/groups/G1044) to download ad
[TAMECAT](https://attack.mitre.org/software/S1193) is a malware that is used by [APT42](https://attack.mitre.org/groups/G1044) to execute PowerShell o
Explore this actor's full graph with Ninja Signal