CacheMoney is a custom Trojan backdoor used by the Iranian-linked espionage group APT39, also tracked as Chafer and Helix Kitten. Reporting states APT39 primarily uses the Seaweed and CacheMoney backdoors, along with a variant of Powbat, after initial compromise to establish a foothold in victim environments. APT39 has targeted telecommunications, travel, and technology services organizations, with activity assessed as focused on intelligence collection, including monitoring, tracking, and surveillance of specific individuals and theft of personal and customer data such as call records and travel itineraries. In the broader intrusion lifecycle associated with APT39, initial access has included spearphishing with malicious attachments or hyperlinks, exploitation of vulnerable web servers to deploy web shells such as ANTAK and ASPXSPY, and use of stolen credentials to access externally facing Outlook Web Access. Post-compromise operations alongside CacheMoney have included credential theft and privilege escalation using tools such as Mimikatz, Windows Credential Editor, ProcDump, and Ncrack; internal reconnaissance with custom tooling including BLUETORCH; lateral movement via RDP, SSH, PsExec, RemCom, and xCmdSvc; and use of REDTRIP, PINKTRIP, and BLUETRIP SOCKS5 proxy tools. Stolen data is typically archived with WinRAR or 7-Zip prior to exfiltration. The provided content does not include specific CacheMoney indicators of compromise such as filenames, hashes, domains, or mutexes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-compromise, APT39 leverages custom backdoors such as SEAWEED, CACHEMONEY, and a unique variant of POWBAT...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.