APT39
Also reported as Chafer, ITG07, Cadelle, Burgundy Sandstorm, TA454 and 7 other names. Linked to Iran by four sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
Show all 53 techniques Show fewer
- T1041
- T1046
- T1053.005
- T1056
- T1056.001
- T1059
- T1059.001
- T1059.005
- T1059.006
- T1059.010
- T1070.004
- T1071.001
- T1071.004
- T1074.001
- T1078
- T1083
- T1090.001
- T1090.002
- T1102.002
- T1105
- T1110
- T1113
- T1115
- T1135
- T1136.001
- T1140
- T1190
- T1197
- T1204.001
- T1204.002
- T1505.003
- T1546.010
- T1547.001
- T1547.009
- T1553.006
- T1555
- T1560.001
- T1566.001
- T1566.002
- T1569.002
- T1588.002
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2015-5119 KEV
- CVE-2017-0213 KEV ransomware
- CVE-2017-10271 KEV ransomware
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-1579
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-8440 KEV ransomware
Show all 20 CVEs Show fewer
- CVE-2018-8639 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-10148 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2021-33766 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
Show all 73 reports Show fewer
-
Chafer, APT 39 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Chafer, APT 39 - Threat Group Cards: A Threat Actor Encyclopedia
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Operation GhostShell_ Novel RAT Targets Global Aerospace and Telecoms Firms
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation GhostShell_ Novel RAT Targets Global Aerospace and Telecoms Firms
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Rana Android Malware Your past catches up, sooner or later...
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rana Android Malware Your past catches up, sooner or later...
-
Elfin- Latest U.S. Indictments Appear to Target Iranian Espionage Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elfin- Latest U.S. Indictments Appear to Target Iranian Espionage Group
-
Counter Terrorism Designations; Iran-Cyber-related Designations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Counter Terrorism Designations; Iran-Cyber-related Designations
-
Treasury Sanctions Cyber Actors Backed by Iranian Intelligence Ministry
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Treasury Sanctions Cyber Actors Backed by Iranian Intelligence Ministry
-
SCANdalous! (External Detection Using Network Scan Data and Automation)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SCANdalous! (External Detection Using Network Scan Data and Automation)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-Chafer-creat4491-en_EN:Bitdefender-PR-Whitepaper-Chafer-creat4491-en_EN.indd
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report-bb-decade-of-the-rats
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Fox Kittens report 16.2.2020
-
xHunt Campaign- New Watering Hole Identified for Credential Harvesting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor xHunt Campaign- New Watering Hole Identified for Credential Harvesting
-
Current Iran-Associated Cyber Threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Current Iran-Associated Cyber Threats
-
Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
New Python-Based Payload MechaFlounder Used by Chafer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Python-Based Payload MechaFlounder Used by Chafer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities
-
Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities
-
APT39- An Iranian Cyber Espionage Group Focused on Personal Information
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT39- An Iranian Cyber Espionage Group Focused on Personal Information
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Let's Learn- Internals of Iranian-Based Threat Group -Chafer- Malware- Autoit and PowerShell Persistence
-
Chafer_ Latest Attacks Reveal Heightened Ambitions _ Symantec Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chafer_ Latest Attacks Reveal Heightened Ambitions _ Symantec Blogs
-
Chafer- Latest Attacks Reveal Heightened Ambitions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chafer- Latest Attacks Reveal Heightened Ambitions
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford _ ClearSky Cybersecurity
-
Iran-based attackers use back door threats to spy on Middle Eastern targets
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iran-based attackers use back door threats to spy on Middle Eastern targets
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iran-based attackers use back door threats to spy on Middle Eastern targets | Symantec Connect Community
-
Iran-based attackers use back door threats to spy on Middle Eastern targets
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Iran-based attackers use back door threats to spy on Middle Eastern targets
Newest first. Details opens the report in Explore.