Skip to content
← All Threat Actors
Nation-State high Iran

APT42

Iranian state-sponsored (IRGC-IO — Islamic Revolutionary Guard Corps Intelligence Organisation) · Espionage — credential theft targeting Western officials, journalists, dissidents, nuclear researchers, and political campaigns

Reports 1
Active Since 2015
Last Reported 18 Jun 2026
Sectors Targeted government, healthcare, communications, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Patient relationship-building social engineering: weeks or months of persona maintenance via Gmail, WhatsApp, Signal, LinkedIn, and phone/video before any credential phishing
  • Real-time phishing frameworks (Evilginx-class) intercepting credentials and session cookies as victims type — bypasses standard SMS-based MFA
  • TAMECAT PowerShell backdoor: lightweight persistent access for targeted post-compromise espionage
  • NICECURL VBScript backdoor and GADGETEER document weaponisation for initial compromise
  • Fake login pages for Google, Microsoft, Yahoo, and ProtonMail — 250+ phishing emails to 35+ targets in documented two-week windows
  • C2 via legitimate cloud services: Google Drive, OneDrive, Google Sites, Telegram — traffic indistinguishable from standard cloud use
  • Targeting of personal accounts (private Gmail, WhatsApp, Signal) rather than corporate — bypasses enterprise security controls entirely

Known Targets

US presidential campaign staff (2024 — Trump campaign breached; Harris campaign targeted)Western government foreign policy officials and diplomatsNuclear policy researchers and academicsHuman rights activists and journalists covering IranIsraeli government and defence officialsIranian diaspora and opposition figures (transnational repression)

Analyst Notes

APT42 is the IRGC-IO's dedicated credential-theft and espionage operation. The 2024 US presidential election targeting — confirmed breach of the Trump campaign with data exfiltrated and passed to the Biden/Harris campaign (which did not engage) — was the most politically significant Iranian cyber operation publicly disclosed. The group's defining technique is patience: months-long persona maintenance before credential phishing yields significantly higher success rates than conventional campaigns. Targeting personal accounts means enterprise MFA enforcement, email security, and endpoint detection are bypassed — the attack surface is individuals' personal digital lives.

Also Known As

Charming Kitten (ClearSky/Check Point — partial overlap)Phosphorus (Microsoft legacy)Mint Sandstorm (Microsoft current)TA453 (Proofpoint)Yellow Garuda (PwC)CALANQUE