APT42 is an Iran-aligned cyberespionage threat actor associated with sustained social-engineering and spear-phishing operations against high-profile individuals and public figures worldwide. The cluster overlaps with activity tracked as Charming Kitten, Mint Sandstorm, and Educated Manicore. Its operations are characterized by long-running impersonation and trust-building efforts, including the use of private messaging platforms, followed by credential theft or malware delivery in support of surveillance and intelligence collection. The actor has been linked to campaigns using politically themed lures in Farsi and malware delivery through disguised shortcut files that execute scripts, install payloads, and display decoy content to mask compromise. Observed payload functionality includes theft of browser encryption material, browser-stored credentials, Telegram data, and keystrokes, along with backdoor capability and data exfiltration to attacker-controlled infrastructure. Tradecraft associated with this cluster includes spear-phishing, credential theft, persistence via scheduled tasks, and broader post-compromise collection activity. The actor is widely assessed as operating in support of Iranian state interests, with targeting that aligns with dissident monitoring, surveillance, and broader espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-aligned spear-phishing and credential-theft activity targeting public figures globally; referenced as a possible code-similarity overlap (not a confirmed attribution) with the CrescentHarvest campaign.
Iran-aligned espionage actor known for spear-phishing and longer-term social engineering to compromise public figures globally, conducting credential theft operations against high-profile individuals across sectors; referenced due to script similarities with the CrescentHarvest campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.