Overview: APT39, also known as Chafer, surveils individuals and entities considered to be a threat to Iranian interests.

Suspected Attribution: Iran – Since 2014, APT39 has conducted cyber espionage activity through the Iranian Ministry of Intelligence and Security (MOIS) using the front company Rana Intelligence Computing, with the goal of tracking individuals and entities considered to be a threat by the MOIS.

Target Sectors: Telecommunications, high-tech, travel industry, government entities, and IT firms that support them, suggesting intent to perform monitoring, tracking, or surveillance ops against specific individuals.

Attack Vectors: Spearphishing with malicious attachments and/or hyperlinks, typically resulting in a POWBAT infection.

Associated Malware: SEAWEED and CACHEMONEY backdoors, along with a specific variant of the POWBAT backdoor. APT39 has not been observed to exploit vulnerabilities.

Related Terms

Advanced Persistent Threat (APT)

An Advanced Persistent Threat (APT) is a targeted and prolonged cyber attack by skilled attackers who gain ...

Anti-Phishing

Techniques and mechanisms implemented in SWGs to detect and block phishing attacks, which attempt to deceive users ...

API Attack Surface

The set of all endpoints and functions exposed by an application programming interface (API) that could be ...

APT35

Overview: APT35, also known as Charming Kitten, Newscaster, or Mint Sandstorm, conducts long-term, ...

APT41

Overview: APT41, also known as Brass Typhoon. Espionage targeting healthcare, telecoms, and the high-tech sector, ...

Aquatic Panda

Overview: Aquatic Panda collects intelligence and conducts industrial espionage. Suspected Attribution: ...

Attack Surface

The total sum of all potential points or areas in a system, network, or application that are susceptible to ...

Attack Surface Analysis

The process of evaluating and understanding the various entry points and potential weaknesses in a system or ...

Attack Surface Reduction

Strategies and practices aimed at minimizing the overall attack surface by eliminating unnecessary services, ...

Backdoor

A hidden entry point or mechanism intentionally left in a system by developers or attackers to bypass security ...

Bandwidth Control

The ability to manage and allocate network bandwidth for web traffic, ensuring optimal performance and preventing ...

Banyan Threat Protection

Banyan Threat Protection is a section within the ITP Policy page, in which an admin can block threats from end ...