Latest Update27/08/2026

Threats Feed

  1. Public

    Iranian APT39 Uses Android Malware for Domestic Surveillance

    The ReversingLabs analysis, based on an FBI report, reveals that the Iranian-backed APT39 (Rana Corp) is using Android malware for state-sponsored surveillance, primarily targeting individuals deemed a threat by the Iranian government. The malware exploits smartphone features such as the camera and microphone to spy on users. It can intercept SMS, record audio, take photos and manipulate network connections. Obfuscation techniques were used, but analysis of an older sample revealed key capabilities for remote monitoring and control. The malware specifically monitors Iranian messaging apps, suggesting domestic surveillance. Targeted sectors include political dissidents and individuals of interest within Iran.

    read more about Iranian APT39 Uses Android Malware for Domestic Surveillance
  2. Public

    Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign

    Rana Intelligence Computing Company (APT39) is an Iranian front group for the Ministry of Intelligence and Security (MOIS) that conducts cyber operations in Asia, Africa, Europe and North America. Its primary targets include the travel, telecommunications, hospitality, academic, and government sectors. Rana used malware delivered via spearphishing, using Visual Basic, PowerShell, AutoIt scripts and BITS malware to steal data, track individuals and maintain persistence. Their campaign targeted over 15 US companies, using scheduled tasks, encryption and obfuscation techniques to evade detection. Rana also deployed Android malware with root access capabilities for C2 communications, audio recording, and photo capture.

    read more about Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign
  3. Public

    Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign

    Rana Intelligence Computing Company (APT39) is an Iranian front group for the Ministry of Intelligence and Security (MOIS) that conducts cyber operations in Asia, Africa, Europe and North America. Its primary targets include the travel, telecommunications, hospitality, academic, and government sectors. Rana used malware delivered via spearphishing, using Visual Basic, PowerShell, AutoIt scripts and BITS malware to steal data, track individuals and maintain persistence. Their campaign targeted over 15 US companies, using scheduled tasks, encryption and obfuscation techniques to evade detection. Rana also deployed Android malware with root access capabilities for C2 communications, audio recording, and photo capture.

    read more about Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign
  4. Public

    Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign

    Rana Intelligence Computing Company (APT39) is an Iranian front group for the Ministry of Intelligence and Security (MOIS) that conducts cyber operations in Asia, Africa, Europe and North America. Its primary targets include the travel, telecommunications, hospitality, academic, and government sectors. Rana used malware delivered via spearphishing, using Visual Basic, PowerShell, AutoIt scripts and BITS malware to steal data, track individuals and maintain persistence. Their campaign targeted over 15 US companies, using scheduled tasks, encryption and obfuscation techniques to evade detection. Rana also deployed Android malware with root access capabilities for C2 communications, audio recording, and photo capture.

    read more about Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign
  5. Public

    Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign

    Rana Intelligence Computing Company (APT39) is an Iranian front group for the Ministry of Intelligence and Security (MOIS) that conducts cyber operations in Asia, Africa, Europe and North America. Its primary targets include the travel, telecommunications, hospitality, academic, and government sectors. Rana used malware delivered via spearphishing, using Visual Basic, PowerShell, AutoIt scripts and BITS malware to steal data, track individuals and maintain persistence. Their campaign targeted over 15 US companies, using scheduled tasks, encryption and obfuscation techniques to evade detection. Rana also deployed Android malware with root access capabilities for C2 communications, audio recording, and photo capture.

    read more about Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign
  6. Public

    Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign

    Rana Intelligence Computing Company (APT39) is an Iranian front group for the Ministry of Intelligence and Security (MOIS) that conducts cyber operations in Asia, Africa, Europe and North America. Its primary targets include the travel, telecommunications, hospitality, academic, and government sectors. Rana used malware delivered via spearphishing, using Visual Basic, PowerShell, AutoIt scripts and BITS malware to steal data, track individuals and maintain persistence. Their campaign targeted over 15 US companies, using scheduled tasks, encryption and obfuscation techniques to evade detection. Rana also deployed Android malware with root access capabilities for C2 communications, audio recording, and photo capture.

    read more about Iranian APT39 Targets Global Sectors with Sophisticated Malware Campaign
  7. Public

    Tracking APT39 and APT34: Innovations in C2 Server Profiling

    In October 2019, Aaron Stephens introduced the SCANdalous project, which automates the profiling of command and control (C2) servers used by threat groups. Prior to automation, analysts manually identified servers linked to groups like APT39 and APT34. APT39 employed SSH tunneling and specific server characteristics to evade detection, while APT34 used QUADAGENT malware and PowerShell-based tools like POSHC2 and POWERTON. These efforts led to early identification of malicious infrastructure, improving threat tracking capabilities.

    read more about Tracking APT39 and APT34: Innovations in C2 Server Profiling
  8. Public

    Unmasking APT39: Cyber Attacks on a Global Scale with Focus on the Middle East

    APT39 is a cyber espionage group known for widespread theft of personal information, predominantly from the telecommunications and travel sectors. The group's operations are globally targeted but primarily concentrated in the Middle East. They involve monitoring, tracking, and conducting surveillance of specific individuals. The techniques used by APT39 include spear phishing, exploiting vulnerable web servers, and credential theft. Furthermore, APT39 deploys backdoors and uses various tools for privilege escalation, reconnaissance, lateral movement, and data extraction.

    read more about Unmasking APT39: Cyber Attacks on a Global Scale with Focus on the Middle East