APT39
Named by MandiantSuspected state sponsor: Islamic Republic of IranAPT39 is an Iranian state-linked cyber espionage group active since at least 2014, first publicly named by Mandiant in 2019. The group is distinguished by its systematic focus on the theft of personal information — particularly from telecommunications and travel companies — to support Iranian surveillance and tracking operations against individuals of interest. APT39 uses spear phishing, web shell deployment, and a suite of custom backdoors including SEAWEED, CACHEMONEY, and POWBAT. Its operations span the Middle East, Europe, and beyond. Symantec tracks the same cluster as Chafer, and IBM as ITG07.
Targeted Regions
EgyptEgypt
Dec 2018 ~ Jan 2019
EuropeEurope
Sep 2020 ~ Sep 2020
IranIran
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020 Sep 2020 ~ Sep 2020
IraqIraq
Dec 2018 ~ Jan 2019
IsraelIsrael
Dec 2018 ~ Jan 2019
KuwaitKuwait
Dec 2018 ~ Jan 2019
Middle EastMiddle East
Sep 2020 ~ Sep 2020
QatarQatar
Dec 2018 ~ Jan 2019
Saudi ArabiaSaudi Arabia
Dec 2018 ~ Jan 2019
SpainSpain
Dec 2018 ~ Jan 2019
TurkeyTurkey
Dec 2018 ~ Jan 2019
United Arab EmiratesUnited Arab Emirates
Dec 2018 ~ Jan 2019
United StatesUnited States
Dec 2018 ~ Jan 2019
Sep 2020 ~ Sep 2020
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.