Google-owned Mandiant reported that APT39, an Iranian state-aligned cyber-espionage group, continues to focus on stealing personal information that can support surveillance, targeting, and broader intelligence collection. The group has been linked to operations against individuals and organizations where identity data, travel records, communications, and other sensitive personal details can be used to track persons of interest and support follow-on intrusion activity.
The reporting highlights APT39 as a persistent espionage actor rather than a financially motivated threat, with operations designed to collect data that advances Iranian intelligence objectives. For defenders, the activity underscores the need to monitor for credential theft, unauthorized access to repositories holding personally identifiable information, and intrusion patterns associated with long-term intelligence gathering against high-value users and institutions.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Google Cloud's Mandiant published a report profiling APT39 as an Iranian cyber-espionage group focused on collecting personal information. The reference does not provide earlier dated events, so the publication itself is the only extractable event.
FireEye published research describing APT39 as an Iranian cyber-espionage group focused on collecting personal information. The report established public reporting on the group's targeting and objectives years before the later Mandiant analysis.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.