APT42 is an Iranian state-linked cyber-espionage group assessed to operate on behalf of the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). It is also known as Charming Kitten, COBALT ILLUSION, Phosphorus, TA453, Yellow Garuda, Educated Manticore, Calanque, and Agent Serpens. The group principally conducts intelligence collection against individuals and organizations relevant to Iranian political, security, foreign-policy, and domestic-security interests, including government and defense personnel, policy experts, journalists, academics, researchers, activists, human-rights defenders, NGOs, and Iran-focused organizations. APT42 specializes in patient, relationship-based social engineering. Operators build trust over days or weeks using fabricated personas, impersonated real people and institutions, conference or interview invitations, research collaboration, and messaging across email and social-media platforms. These operations deliver credential-harvesting pages, capture authentication codes to bypass non-hardware MFA, and in some cases deliver malware. The group has used AI-assisted research, translation, persona development, and lure creation to improve the plausibility and multilingual consistency of phishing activity. Post-compromise operations include collection from email, cloud-storage, calendar, contact, and social-media accounts, including bulk exports of account data. APT42 has used browser credential and cookie theft, enabling abuse of session material that can preserve access after password changes. Its TAMECAT malware supports host and file discovery, command execution, screenshot capture, Outlook data collection, browser credential and cookie theft, and data exfiltration through web and messaging-based channels. APT42 has also used security-software discovery, including WMI-based antivirus checks, to tailor activity and evade defenses. The group has demonstrated malware-enabled delivery chains involving Windows search and WebDAV functionality alongside credential-only operations, reflecting a flexible approach focused on durable access and intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
164 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Using TAMECAT to collect browser credentials, cookies, and Windows/WebDAV-related data.
Iranian intelligence-collection threat actor conducting spear-phishing campaigns against individuals associated with the nuclear energy sector, using TAMECAT for surveillance, collection, and resilient command-and-control.
Conducting AI-assisted phishing and intelligence-collection operations against U.S. organizations, using rapport-building social engineering and evolving delivery, persistence, and recovery methods.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.