Threats Feed|APT39|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date29/01/2019

Unmasking APT39: Cyber Attacks on a Global Scale with Focus on the Middle East

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation,Backdoor,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

APT39 is a cyber espionage group known for widespread theft of personal information, predominantly from the telecommunications and travel sectors. The group's operations are globally targeted but primarily concentrated in the Middle East. They involve monitoring, tracking, and conducting surveillance of specific individuals. The techniques used by APT39 include spear phishing, exploiting vulnerable web servers, and credential theft. Furthermore, APT39 deploys backdoors and uses various tools for privilege escalation, reconnaissance, lateral movement, and data extraction.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
SectorInformation Technology
Verified
SectorTelecommunication
Verified
SectorTransportation
The sectors targeted by the APT39 attack, as indicated in the report, are primarily the telecommunications sector, with additional targeting of the travel industry, IT firms that support these sectors, and the high-tech industry. The report also suggests targeting of government entities, implying that the public sector may have been a target as well.
Verified
RegionEgypt
Verified
RegionIraq
Verified
RegionIsrael
High
RegionKuwait
Verified
RegionQatar
High
RegionSaudi Arabia
Verified
RegionSpain
Verified
RegionTurkey
Verified
RegionUnited Arab Emirates
Verified
RegionUnited States
Verified

FAQs

Frequently Asked Questions About APT39's Cyber Espionage Campaign

In December 2018, FireEye identified APT39 as an Iranian cyber espionage group responsible for a sustained, large-scale campaign stealing personal information from organizations across the globe. The group has been active since at least November 2014, targeting telecommunications companies, travel firms, and IT providers — primarily in the Middle East — to collect data on individuals of interest to the Iranian government.

APT39 is an Iranian state-sponsored cyber espionage group. FireEye assessed with moderate confidence that the group operates in support of Iranian national interests, based on its regional targeting patterns, infrastructure, and operational timing. The group shares some similarities with APT34 (also known as OilRig), including malware delivery methods and infrastructure naming conventions, but is tracked as a distinct actor due to its use of a different POWBAT backdoor variant.

The campaign is a long-running cyber espionage operation focused on collecting personal information — including travel itineraries, communication records, and customer data — to enable surveillance and tracking of specific individuals. The goal is to support Iranian national security priorities, which may include monitoring dissidents, tracking persons of interest, and gathering geopolitical intelligence from government entities.

APT39's targeting is global but concentrated in the Middle East. Confirmed victim countries include Egypt, Iraq, Israel, Kuwait, Qatar, Saudi Arabia, Spain, Turkey, the United Arab Emirates, and the United States. The group has been active for over a decade, running persistent intrusion campaigns across multiple continents, making it one of the more broadly active Iranian espionage actors tracked by Western intelligence firms.

APT39 primarily targets the telecommunications and travel sectors, along with IT firms that support them and the high-tech industry. Government entities have also been targeted, likely to collect geopolitical intelligence. Individuals of interest to the Iranian government — including dissidents, dual nationals, and people with connections to foreign governments — are the ultimate targets of the data collection, with telecom and travel companies serving as conduits to reach them.

APT39 typically gained initial access through spear phishing emails containing malicious attachments or links, exploitation of vulnerable public-facing web servers to install web shells, or abuse of stolen credentials against services like Outlook Web Access. Once inside, the group deployed custom backdoors (SEAWEED, CACHEMONEY, POWBAT) for persistence, used tools like Mimikatz and ProcDump to harvest credentials, and moved laterally using RDP, SSH, and PsExec. Custom SOCKS5 proxy tools (REDTRIP, PINKTRIP, BLUETRIP) were used to tunnel traffic between infected hosts, and collected data was archived with WinRAR or 7-Zip before being exfiltrated.

Telecommunications and travel companies hold large volumes of personal data — including call records, travel itineraries, and customer identities — that can be used to track and monitor individuals of interest to the Iranian government. IT firms supporting these sectors are also targeted because compromising them can provide indirect access to the same data at scale. Government entities are targeted for geopolitical intelligence. In short, these sectors serve as aggregators of exactly the kind of personal information APT39 needs for its surveillance mission.

Organizations in the telecommunications, travel, and IT sectors should enforce multi-factor authentication on all externally facing services, especially Outlook Web Access and VPN gateways. Lateral movement paths should be restricted by monitoring and limiting use of RDP, SSH, and admin tools like PsExec between workstations. Endpoint detection capable of identifying credential dumping tools such as Mimikatz and ProcDump should be deployed. Internet-facing web servers should be patched promptly and regularly audited for unauthorized web shells. Network segmentation, data access controls, and logging coverage for customer data repositories should all be reviewed and hardened.

About Affiliation
APT39
APT39 is an Iranian state-linked cyber espionage group active since at least 2014, first publicly named by Mandiant in 2019. The group is distinguished by its systematic focus on the theft of personal information — particularly from telecommunications and travel companies — to support Iranian surveillance and tracking operations against individuals of interest. APT39 uses spear phishing, web shell deployment, and a suite of custom backdoors including SEAWEED, CACHEMONEY, and POWBAT. Its operations span the Middle East, Europe, and beyond. Symantec tracks the same cluster as Chafer, and IBM as ITG07.
View APT39's Insights