Actors Insights|Latest update04/07/2026

APT39 Cluster

Suspected state sponsor: Islamic Republic of Iran

APT39 is an Iranian state-sponsored threat cluster active since at least 2014, assessed with moderate confidence to operate in support of Iran's Ministry of Intelligence and Security (MOIS). Unlike Iranian groups focused on destruction or influence operations, APT39's defining characteristic is the large-scale theft of personal information — a mission that reflects Iran's interest in tracking, monitoring, and surveilling individuals both inside and outside its borders.

 

Targets and Goals

APT39 has prioritized the telecommunications and travel industries above all others, with secondary targeting of IT service providers, government entities, and the high-tech sector. Its geographic reach is global, with the heaviest concentration of operations in the Middle East. The collection of personal data such as travel itineraries, call records, and customer databases from telecom providers points to a surveillance mission rather than a purely financial or destructive one. The US Treasury Department linked APT39 activity to Rana Intelligence Computing, an Iranian company assessed to be a front for MOIS cyber operations.

 

Tooling and Tactics

APT39 gains initial access through spear phishing emails with malicious attachments, exploitation of vulnerable public-facing web servers, and abuse of stolen credentials against Outlook Web Access (OWA) systems. After gaining a foothold, the group deploys custom backdoors — SEAWEED, CACHEMONEY, and a unique POWBAT variant — alongside web shells such as ANTAK and ASPXSPY. For lateral movement, APT39 uses RDP, SSH, PsExec, and custom SOCKS5 proxy tools (REDTRIP, PINKTRIP, BLUETRIP). Credential harvesting relies on Mimikatz and Ncrack, and stolen data is compressed with WinRAR or 7-Zip before exfiltration.

 

Aliases

APT39 is tracked as Chafer by Symantec, ITG07 by IBM, and Remix Kitten by CrowdStrike. The sub-identity Rana Intelligence Computing reflects the US government's formal attribution of the group's infrastructure to an MOIS-linked front company. Cadelspy and Remexi refer to specific malware families associated with cluster activity documented in US government indictments.

Most Common Tactics

Targeted Regions

Afghanistan
AF
Afghanistan
Afghanistan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Egypt
EG
Egypt
Egypt
Dec 2018 ~ Jan 2019
Europe
EU
Europe
Europe
Sep 2020 ~ Sep 2020
Germany
DE
Germany
Germany
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Iran
IR
Iran
Iran
Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020
Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020
Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020
Jul 2014 ~ Dec 2015
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Mar 2018 ~ Jan 2019
Dec 2014 ~ Dec 2020
Mar 2018 ~ Jan 2019
Dec 2014 ~ Dec 2020
Mar 2018 ~ Jan 2019
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Dec 2014 ~ Dec 2020
Sep 2020 ~ Sep 2020
Iraq
IQ
Iraq
Iraq
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Dec 2018 ~ Jan 2019
Israel
IL
Israel
Israel
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Dec 2018 ~ Jan 2019
Jordan
JO
Jordan
Jordan
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Kuwait
KW
Kuwait
Kuwait
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
Dec 2018 ~ Jan 2019
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
Middle East
ME
Middle East
Middle East
Sep 2020 ~ Sep 2020
Netherlands
NL
Netherlands
Netherlands
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Pakistan
PK
Pakistan
Pakistan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Qatar
QA
Qatar
Qatar
Dec 2018 ~ Jan 2019
Saudi Arabia
SA
Saudi Arabia
Saudi Arabia
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2018 ~ May 2020
Jan 2017 ~ Feb 2018
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
Dec 2018 ~ Jan 2019
Jan 2018 ~ May 2020
Jan 2018 ~ May 2020
Singapore
SG
Singapore
Singapore
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Spain
ES
Spain
Spain
Dec 2018 ~ Jan 2019
Sudan
SD
Sudan
Sudan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Tajikistan
TJ
Tajikistan
Tajikistan
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Thailand
TH
Thailand
Thailand
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Turkey
TR
Turkey
Turkey
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Nov 2018 ~ Mar 2019
Nov 2018 ~ Mar 2019
Dec 2018 ~ Jan 2019
United Arab Emirates
AE
United Arab Emirates
United Arab Emirates
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Jan 2017 ~ Feb 2018
Dec 2018 ~ Jan 2019
United Kingdom
GB
United Kingdom
United Kingdom
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
United States
US
United States
United States
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Jul 2014 ~ Dec 2015
Dec 2018 ~ Jan 2019
Sep 2020 ~ Sep 2020
Jan 2014Jun 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.