SpearSpecter is an Iranian state-aligned espionage threat actor assessed with high confidence to be aligned with the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). The content identifies SpearSpecter as operating under multiple aliases, including APT42, Mint Sandstorm, Educated Manticore, and CharmingCypress. Based on the provided content, APT42 is the most widely recognized name. The campaign described is focused on long-term intelligence collection against individuals and organizations of interest to the IRGC, with systematic targeting of senior government and defense officials and, in some cases, their family members. The operators rely on prolonged, personalized social engineering rather than mass phishing, including direct WhatsApp outreach, fake conference or strategic meeting invitations, and spoofed meeting pages used for real-time credential harvesting. For persistent access and collection, the actor deploys the modular PowerShell backdoor TAMECAT. The observed infection chain used redirects to lure content hosted on OneDrive, abuse of the Windows search-ms protocol, attacker-controlled WebDAV infrastructure, and malicious LNK files disguised as documents. Execution led to use of cmd.exe, curl.exe, Cloudflare Workers-hosted staging, and obfuscated PowerShell loaders. TAMECAT is described as largely fileless and memory-resident, with persistence via registry Run keys, UserInitMprLogonScript, and scripts stored under user profile paths. The malware supports reconnaissance, remote command execution, browser data theft, screenshot capture, document and archive collection, Outlook OST theft, and staged exfiltration. It uses multiple command-and-control channels, including HTTPS, Telegram, and Discord; the report states this is the first recorded instance of APT42 using Telegram and Discord for C2. Additional tradecraft noted in the content includes AES-256-encrypted exfiltration, use of LOLBins and trusted binaries such as rundll32.exe, conhost.exe, msedge.exe, cmd.exe, curl.exe, and PowerShell, runtime obfuscation, registry-based persistence, Firebase signaling, and Cloudflare Workers-backed infrastructure. The content states that the infrastructure and tradecraft strongly align with previously documented APT42 operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SpearSpecter (APT42) is an Iranian APT group known for cyber-espionage operations, often targeting individuals and organizations of strategic interest to Iran.
Described as an Iran-linked APT conducting a campaign using weeks-long WhatsApp social-engineering lures and deploying a fileless backdoor (TAMECAT) to target the defense sector.
Iran-aligned espionage campaign targeting high-value senior defense and government officials through long-term relationship-building social engineering, credential harvesting, and deployment of the modular TAMECAT backdoor for persistence, reconnaissance, data theft, and covert exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.