APT34, also known as Evasive Serpens, is an Iranian state-aligned cyber espionage group associated with broad targeting in support of nation-state interests. The group is known for intelligence collection operations and has been publicly linked to spear-phishing campaigns, credential harvesting, and DNS hijacking. Its activity fits the broader pattern of Iranian intrusion sets that prioritize espionage and disruptive access against critical infrastructure and sensitive sectors. APT34 is regarded as a prolific operator within the Iranian threat ecosystem. Its tradecraft centers on obtaining initial access through targeted phishing and related social-engineering activity, followed by theft of credentials and post-compromise abuse of victim access. The group has also been associated with infrastructure manipulation techniques such as DNS hijacking, which can support credential collection, traffic redirection, and broader espionage objectives. Evasive Serpens is one of several tracked Iranian threat groups operating alongside clusters such as APT42, MuddyWater, Peach Sandstorm, Imperial Kitten, and Chrono Kitten. Within that ecosystem, APT34 is most consistently characterized as an espionage-focused actor rather than a ransomware or financially motivated group. Its operations align with Iranian strategic priorities and have been discussed in the context of heightened regional tensions involving Iran, Israel, and the United States, where Iranian cyber actors are assessed as posing elevated risk to critical infrastructure and other sensitive organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.