APT42
Iranian state-sponsored (IRGC-IO — Islamic Revolutionary Guard Corps Intelligence Organisation) · Espionage — credential theft targeting Western officials, journalists, dissidents, nuclear researchers, and political campaigns
Tactics, Techniques & Procedures (TTPs)
- Patient relationship-building social engineering: weeks or months of persona maintenance via Gmail, WhatsApp, Signal, LinkedIn, and phone/video before any credential phishing
- Real-time phishing frameworks (Evilginx-class) intercepting credentials and session cookies as victims type — bypasses standard SMS-based MFA
- TAMECAT PowerShell backdoor: lightweight persistent access for targeted post-compromise espionage
- NICECURL VBScript backdoor and GADGETEER document weaponisation for initial compromise
- Fake login pages for Google, Microsoft, Yahoo, and ProtonMail — 250+ phishing emails to 35+ targets in documented two-week windows
- C2 via legitimate cloud services: Google Drive, OneDrive, Google Sites, Telegram — traffic indistinguishable from standard cloud use
- Targeting of personal accounts (private Gmail, WhatsApp, Signal) rather than corporate — bypasses enterprise security controls entirely
Known Targets
Analyst Notes
APT42 is the IRGC-IO's dedicated credential-theft and espionage operation. The 2024 US presidential election targeting — confirmed breach of the Trump campaign with data exfiltrated and passed to the Biden/Harris campaign (which did not engage) — was the most politically significant Iranian cyber operation publicly disclosed. The group's defining technique is patience: months-long persona maintenance before credential phishing yields significantly higher success rates than conventional campaigns. Targeting personal accounts means enterprise MFA enforcement, email security, and endpoint detection are bypassed — the attack surface is individuals' personal digital lives.
Also Known As
MITRE ATT&CK Techniques