APT34 is an Iran-linked cyber espionage threat actor commonly tracked as APT34 and widely associated with activity aligned to Iranian state interests. The group is known for identity-centric intrusions, phishing-led credential theft, remote access operations, and the maintenance of persistent footholds in victim environments. Reporting places APT34 among the Iranian actors organizations should expect during periods of regional crisis, particularly where cloud identity infrastructure, remote administration, and supply-chain relationships create opportunities for compromise. The actor has been associated with targeting of energy, financial services, telecommunications, government-related entities, and broader supply-chain ecosystems. Iran-linked intrusion sets in this cluster have also been discussed in relation to healthcare, logistics, aviation, critical infrastructure, and organizations with ties to the Middle East, especially during escalatory geopolitical events. Tradecraft attributed to this ecosystem includes phishing, credential theft, use of remote access tooling, persistence in Western networks, and evolution toward cloud-focused and identity-focused post-compromise activity. The operational objective is consistent with state-directed intelligence collection and strategic access rather than criminal monetization. APT34 is part of the broader landscape of Iranian state-aligned cyber operations that use proxies and front organizations to complicate attribution. The group is frequently discussed alongside other Iran-linked actors such as APT33 and OilRig in analyses of Iranian cyber activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.