APT42 is an Iranian state-linked cyber espionage threat actor widely assessed to operate on behalf of the Islamic Revolutionary Guard Corps Intelligence Organization (IRGC-IO). It is best known for highly targeted credential theft, surveillance, and account compromise operations against individuals and organizations of strategic interest to the Iranian government. Common aliases include Charming Kitten, Mint Sandstorm, and Educated Manticore. APT42 primarily targets journalists, researchers, dissidents, activists, civil society organizations, non-profits, political consultants, government officials, and diplomatic or policy communities, with activity observed across the Middle East, Europe, and the United States. The group has also targeted election-related entities and high-profile political figures, and has conducted operations aligned with Iranian intelligence collection priorities, including monitoring perceived domestic threats and persons of interest. A defining characteristic of APT42 is its heavy reliance on social engineering and identity-focused intrusion tradecraft rather than malware-heavy operations. The group commonly impersonates legitimate people or trusted organizations, establishes rapport over time through email or messaging platforms, and then delivers credential-harvesting lures. Reported techniques include adversary-in-the-middle phishing, MFA interception, MFA fatigue or push-bombing, session hijacking, and abuse of valid accounts. After compromise, APT42 often leverages built-in cloud and enterprise features—especially within Microsoft 365 environments—for collection, persistence, and stealth, reducing endpoint artifacts and complicating detection. Although APT42 is especially associated with malware-light credential theft, it has also used malware and tooling in some operations. Public reporting has linked the actor to tools and malware including NICECURL, GHAMBAR, POWERPOST, and VINETHORN. Observed tradecraft includes HTTPS-based command and control, Base64-encoded communications, system information collection, use of anonymized infrastructure and virtual private servers, scheduled tasks for persistence, registry modification for persistence, and masquerading payloads as legitimate software such as VPN applications. APT42 should be distinguished from other Iranian intrusion sets such as MuddyWater/Seedworm, which is more commonly associated with broader enterprise intrusion activity, malware deployment, and remote management tool abuse. In contrast, APT42 is particularly notable for selecting victims based on their access, relationships, and information value, then compromising accounts to support espionage, surveillance, and occasionally hack-and-leak style influence objectives. Its operations exemplify Iran’s mature use of social engineering, cloud account compromise, and low-malware intrusion methods in support of state intelligence goals.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
86 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IRGC-linked Iranian group conducting credential theft through social engineering and MFA bypass without malware.
Iranian cyber-espionage group focused on targeting specific individuals such as journalists, researchers, dissidents, and political consultants. The group uses social engineering, credential harvesting, adversary-in-the-middle phishing, MFA interception, session cookie theft, and then operates inside cloud services such as Microsoft 365 for email and document collection without deploying malware on endpoints.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Uses social engineering priming to build trust with victims before delivering malicious files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.