APT39
Also known as: burgundy sandstorm, chafer, cinder ion, cobalt hickman, g0087, itg07, radio serpens, remix kitten, ta454
[APT39](https://attack.mitre.org/groups/G0087) is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. [APT39](https://attack.mitre.org/groups/G0087) has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.(Citation: FireEye APT39 Jan 2019)(Citation: Symantec Chafer Dec 2015)(Citation: FBI FLASH APT39 September 2020)(Citation: Dept. of Treasury Iran Sanctions September 2020)(Citation: DOJ Iran Indictments September 2020)
Most affected countries
No data yet.
Most affected sectors
No data yet.
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- Privileged Account Management (13 techniques covered)
- User Account Management (10 techniques covered)
- Network Intrusion Prevention (10 techniques covered)
- Execution Prevention (9 techniques covered)
- User Training (7 techniques covered)
- Behavior Prevention on Endpoint (7 techniques covered)
- Disable or Remove Feature or Program (7 techniques covered)
- Audit (7 techniques covered)
MITRE ATT&CK techniques
Recent victims
No data yet.
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.