APT39 Cluster
Suspected state sponsor: Islamic Republic of IranAPT39 is an Iranian state-sponsored threat cluster active since at least 2014, assessed with moderate confidence to operate in support of Iran's Ministry of Intelligence and Security (MOIS). Unlike Iranian groups focused on destruction or influence operations, APT39's defining characteristic is the large-scale theft of personal information — a mission that reflects Iran's interest in tracking, monitoring, and surveilling individuals both inside and outside its borders.
Targets and Goals
APT39 has prioritized the telecommunications and travel industries above all others, with secondary targeting of IT service providers, government entities, and the high-tech sector. Its geographic reach is global, with the heaviest concentration of operations in the Middle East. The collection of personal data such as travel itineraries, call records, and customer databases from telecom providers points to a surveillance mission rather than a purely financial or destructive one. The US Treasury Department linked APT39 activity to Rana Intelligence Computing, an Iranian company assessed to be a front for MOIS cyber operations.
Tooling and Tactics
APT39 gains initial access through spear phishing emails with malicious attachments, exploitation of vulnerable public-facing web servers, and abuse of stolen credentials against Outlook Web Access (OWA) systems. After gaining a foothold, the group deploys custom backdoors — SEAWEED, CACHEMONEY, and a unique POWBAT variant — alongside web shells such as ANTAK and ASPXSPY. For lateral movement, APT39 uses RDP, SSH, PsExec, and custom SOCKS5 proxy tools (REDTRIP, PINKTRIP, BLUETRIP). Credential harvesting relies on Mimikatz and Ncrack, and stolen data is compressed with WinRAR or 7-Zip before exfiltration.
Aliases
APT39 is tracked as Chafer by Symantec, ITG07 by IBM, and Remix Kitten by CrowdStrike. The sub-identity Rana Intelligence Computing reflects the US government's formal attribution of the group's infrastructure to an MOIS-linked front company. Cadelspy and Remexi refer to specific malware families associated with cluster activity documented in US government indictments.
observatory results
APT39
APT39 is named by Mandiant and at the moment 4 indexed report with 60 related IOCs
Cadelspy
Cadelspy is named by Symantec and at the moment 0 indexed report with 0 related IOCs
Chafer
Chafer is named by Symantec and at the moment 6 indexed report with 161 related IOCs
ITG07
ITG07 is named by IBM and at the moment 1 indexed report with 13 related IOCs
Rana Intelligence Computing
Rana Intelligence Computing is named by real name and at the moment 0 indexed report with 0 related IOCs
Remexi
Remexi is named by Symantec and at the moment 0 indexed report with 0 related IOCs
Most Common Tactics
Targeted Regions
AfghanistanAfghanistan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
EgyptEgypt
Dec 2018 ~ Jan 2019
EuropeEurope
Sep 2020 ~ Sep 2020
GermanyGermany
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
IranIran
Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020 Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020 Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020 Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020 Mar 2018 ~ Jan 2019
Dec 2014 ~ Dec 2020 Mar 2018 ~ Jan 2019
Dec 2014 ~ Dec 2020 Mar 2018 ~ Jan 2019
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020 Sep 2020 ~ Sep 2020
IraqIraq
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Dec 2018 ~ Jan 2019
IsraelIsrael
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Dec 2018 ~ Jan 2019
JordanJordan
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
KuwaitKuwait
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020 Dec 2018 ~ Jan 2019
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
Middle EastMiddle East
Sep 2020 ~ Sep 2020
NetherlandsNetherlands
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
PakistanPakistan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
QatarQatar
Dec 2018 ~ Jan 2019
Saudi ArabiaSaudi Arabia
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2018 ~ May 2020 Jan 2017 ~ Feb 2018
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020 Dec 2018 ~ Jan 2019
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
SingaporeSingapore
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
SpainSpain
Dec 2018 ~ Jan 2019
SudanSudan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
TajikistanTajikistan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
ThailandThailand
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
TurkeyTurkey
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Nov 2018 ~ Mar 2019
Nov 2018 ~ Mar 2019 Dec 2018 ~ Jan 2019
United Arab EmiratesUnited Arab Emirates
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Dec 2018 ~ Jan 2019
United KingdomUnited Kingdom
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
United StatesUnited States
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Dec 2018 ~ Jan 2019
Sep 2020 ~ Sep 2020
Recent Activities
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.