APT42__2022__APT42_Crooked_Charms_Cons_and_Compromises.pdf
ID: c4a084ca-6663-4f19-90b0-62a77e2ae1e3
STIX ID: report--c4a084ca-6663-4f19-90b0-62a77e2ae1e3
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2022-09-01
Last Modified Date: 2022-09-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant assesses with high confidence that APT42 is an Iranian state-sponsored cyber espionage group active since at least 2015 that conducts highly targeted credential-harvesting and surveillance operations—primarily via patient spear-phishing, MFA interception, and Android malware (e.g., PINEFLOWER, VINETHORN)—against journalists, dissidents, think tanks, academics, and government officials; the report provides TTPs, malware family descriptions, extensive IOCs, MITRE ATT&CK mappings, historical context, and attribution to Iranian intelligence.
