APT42 is an Iranian state-sponsored cyber espionage actor widely tracked under the aliases Charming Kitten, Mint Sandstorm, and GreenBravo. The group is associated with Iran and operates as part of the country’s broader intelligence and hybrid warfare ecosystem. It is known for credential-focused intrusion activity, social engineering, and targeted operations aligned with Iranian strategic interests. APT42 has been linked to spearphishing and other initial-access tradecraft, as well as reconnaissance, credential theft, and post-compromise activity. Reporting also indicates use of generative AI tooling to accelerate development of specialized malicious capabilities, including debugging, code generation, and research into exploitation techniques. This reflects an evolution in workflow efficiency rather than a fundamental change in the group’s underlying tradecraft. The actor fits within the broader pattern of Iranian cyber operations that emphasize deniable, asymmetric capabilities and persistent targeting of foreign governments and strategic interests. Known aliases include Charming Kitten, Mint Sandstorm, and GreenBravo.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian threat actor using Gemini to accelerate development of malicious tooling, including debugging, code generation, and exploitation research.
Iran-linked threat actor using Gemini to accelerate development of specialized malicious tools, including debugging, code generation, and exploitation research.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.