IRconfidence: 50G0087

APT39APT39

Also known as: Chafer · REMIX KITTEN · COBALT HICKMAN · G0087 · Radio Serpens · TA454 · ITG07 · Burgundy Sandstorm · APT39

Origin
IR
Known aliases
9
Attribution
50

Profile

APT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a group publicly referred to as "Chafer." However, there are differences in what has been publicly reported due to the variances in how organizations track activity. APT39 primarily leverages the SEAWEED and CACHEMONEY backdoors along with a specific variant of the POWBAT backdoor. While APT39's targeting scope is global, its activities are concentrated in the Middle East. APT39 has prioritized the telecommunications sector, with additional targeting of the travel industry and IT firms that support it and the high-tech industry.

Aliases· 9

ChaferREMIX KITTENCOBALT HICKMANRadio SerpensTA454ITG07Burgundy SandstormAPT39
G0087

MITRE ATT&CK Group crosswalk

G0087

References

  1. https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html
  2. https://www.symantec.com/blogs/threat-intelligence/chafer-latest-attacks-reveal-heightened-ambitions
  3. https://unit42.paloaltonetworks.com/new-python-based-payload-mechaflounder-used-by-chafer/
  4. https://securelist.com/chafer-used-remexi-malware/89538/
  5. https://www.symantec.com/connect/blogs/iran-based-attackers-use-back-door-threats-spy-middle-eastern-targets
  6. https://attack.mitre.org/groups/G0087/
  7. https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf
  8. https://www.secureworks.com/research/threat-profiles/cobalt-hickman

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT37
Actor
APT33
Actor
APT35
Actor
APT19
Actor
APT9
Actor
APT41
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.