Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: ITG07, Chafer, Remix Kitten
53
techniques
11
software
11,779
corpus matches
profile
APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.
techniques
53 attributed · most-instrumented first
software
11 malware & tools attributed
Mimikatz
S0002
Windows Credential Editor
S0005
pwdump
S0006
PsExec
S0029
ASPXSpy
S0073
ftp
S0095
Remexi
S0375
Cadelspy
S0454
MechaFlounder
S0459
CrackMapExec
S0488
read this carefully
11,779 corpus matches is not attribution
That count is indicators which exhibit techniques APT39 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+41 more techniques
NBTscan
S0590
showing 30 of 11,779
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.