Actors Insights|Latest update04/07/2026
ITG07
Named by IBMSuspected state sponsor: Islamic Republic of IranITG07 is IBM X-Force's designation for the Iranian threat cluster known as APT39. Active since at least 2014, the group focuses on espionage and personal information theft targeting telecommunications, travel, and government organizations. IBM's tracking of this cluster aligns closely with Mandiant's APT39 and Symantec's Chafer reporting, covering the same TTPs: spear phishing, web shell deployment, custom backdoor usage, and large-scale data collection. The cluster is assessed to operate in support of Iranian state surveillance interests.
First Seen:Sep 2018
Last Seen:Sep 2020
Indexed Reports:1
Public IOCs:13
also known as:
Chafer (Symantec)Remix Kitten (CrowdStrike)COBALT HICKMAN (SecureWorks)G0087 (Mitre)Radio Serpens (Palo Alto)TA454 (Proofpoint)ITG07 (IBM)Burgundy SandstormAPT39 (Mandiant)
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.