Actors Insights|Latest update04/07/2026

ITG07

Named by IBMSuspected state sponsor: Islamic Republic of Iran

ITG07 is IBM X-Force's designation for the Iranian threat cluster known as APT39. Active since at least 2014, the group focuses on espionage and personal information theft targeting telecommunications, travel, and government organizations. IBM's tracking of this cluster aligns closely with Mandiant's APT39 and Symantec's Chafer reporting, covering the same TTPs: spear phishing, web shell deployment, custom backdoor usage, and large-scale data collection. The cluster is assessed to operate in support of Iranian state surveillance interests.

First Seen:Sep 2018
Last Seen:Sep 2020
Indexed Reports:1
Public IOCs:13
Cluster: APT39Mitre: APT39Misp: APT39
also known as:
Chafer (Symantec)Remix Kitten (CrowdStrike)COBALT HICKMAN (SecureWorks)G0087 (Mitre)Radio Serpens (Palo Alto)TA454 (Proofpoint)ITG07 (IBM)Burgundy SandstormAPT39 (Mandiant)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.