APT42
3
3
17.08.2026
09.09.2026
Profil laut MITRE ATT&CK
APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools. APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.
Vollständiges MITRE-ProfilBeschreibung und Alias-Namen stammen aus MITRE ATT&CK®.
Nennungen im Zeitverlauf
Meldungen je Monat, letzte 12 Monate.
Beobachtete Techniken
ATT&CK-Techniken, die in denselben Meldungen benannt sind — nicht das vollständige MITRE-Repertoire.
T1566 Phishing
Initial Access
T1587.001 Malware
Resource Development
T1588.001 Malware
Resource Development
T1587.004 Exploits
Resource Development
T1588.005 Exploits
Resource Development
T1588.007 Artificial Intelligence
Resource Development
T1589.001 Credentials
Reconnaissance
T1589.002 Email Addresses
Reconnaissance
T1592.002 Software
Reconnaissance
T1684 Social Engineering
stealth
T1036 Masquerading
stealth
T1059.006 Python
Execution
Gemeinsam genannt
Betroffene Branchen
Meldungen
AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Quellen: The Hacker News (2), SecurityWeek (1)
Alle Angaben auf dieser Seite stammen aus dem Alias-Abgleich der Meldungstexte gegen den MITRE-ATT&CK-Katalog. Beziehungen entstehen rein statistisch: Zwei Einträge gelten als verbunden, wenn sie in derselben Meldung benannt sind. Das ist keine eigenständige Attribution durch SecBoard, und eine Nennung ist kein Nachweis einer Täterschaft.