« All threats

APT groupMITRE G0087

APT39

Also known as: burgundy sandstorm, chafer, cinder ion, cobalt hickman, g0087, itg07, radio serpens, remix kitten, ta454

[APT39](https://attack.mitre.org/groups/G0087) is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. [APT39](https://attack.mitre.org/groups/G0087) has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.(Citation: FireEye APT39 Jan 2019)(Citation: Symantec Chafer Dec 2015)(Citation: FBI FLASH APT39 September 2020)(Citation: Dept. of Treasury Iran Sanctions September 2020)(Citation: DOJ Iran Indictments September 2020)

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. Privileged Account Management (13 techniques covered)
  2. User Account Management (10 techniques covered)
  3. Network Intrusion Prevention (10 techniques covered)
  4. Execution Prevention (9 techniques covered)
  5. User Training (7 techniques covered)
  6. Behavior Prevention on Endpoint (7 techniques covered)
  7. Disable or Remove Feature or Program (7 techniques covered)
  8. Audit (7 techniques covered)

MITRE ATT&CK techniques

T1046 · Network Service DiscoveryT1547.001 · Registry Run Keys / Startup FolderT1090.002 · External ProxyT1140 · Deobfuscate/Decode Files or InformationT1056.001 · KeyloggingT1005 · Data from Local SystemT1059.001 · PowerShellT1115 · Clipboard DataT1553.006 · Code Signing Policy ModificationT1546.010 · AppInit DLLsT1547.009 · Shortcut ModificationT1135 · Network Share DiscoveryT1569.002 · Service ExecutionT1027.013 · Encrypted/Encoded FileT1588.002 · ToolT1021.001 · Remote Desktop ProtocolT1033 · System Owner/User DiscoveryT1027.002 · Software PackingT1041 · Exfiltration Over C2 ChannelT1204.002 · Malicious FileT1053.005 · Scheduled TaskT1070.004 · File DeletionT1102.002 · Bidirectional CommunicationT1560.001 · Archive via UtilityT1505.003 · Web ShellT1105 · Ingress Tool TransferT1059.010 · AutoHotKey & AutoITT1204.001 · Malicious LinkT1555 · Credentials from Password StoresT1113 · Screen CaptureT1003.001 · LSASS MemoryT1018 · Remote System DiscoveryT1071.004 · DNST1059 · Command and Scripting InterpreterT1074.001 · Local Data StagingT1083 · File and Directory DiscoveryT1012 · Query RegistryT1110 · Brute ForceT1197 · BITS JobsT1136.001 · Local AccountT1059.006 · PythonT1036.005 · Match Legitimate Resource Name or LocationT1071.001 · Web ProtocolsT1090.001 · Internal ProxyT1078 · Valid AccountsT1056 · Input CaptureT1566.002 · Spearphishing LinkT1566.001 · Spearphishing AttachmentT1021.002 · SMB/Windows Admin SharesT1190 · Exploit Public-Facing ApplicationT1059.005 · Visual BasicT1021.004 · SSHT1003 · OS Credential Dumping

Recent victims

No data yet.

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.