logo

APT42__2022__APT42_Crooked_Charms_Cons_and_Compromises.pdf

ID: c4a084ca-6663-4f19-90b0-62a77e2ae1e3

STIX ID: report--c4a084ca-6663-4f19-90b0-62a77e2ae1e3

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2022-09-01

Last Modified Date: 2022-09-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant assesses with high confidence that APT42 is an Iranian state-sponsored cyber espionage group active since at least 2015 that conducts highly targeted credential-harvesting and surveillance operations—primarily via patient spear-phishing, MFA interception, and Android malware (e.g., PINEFLOWER, VINETHORN)—against journalists, dissidents, think tanks, academics, and government officials; the report provides TTPs, malware family descriptions, extensive IOCs, MITRE ATT&CK mappings, historical context, and attribution to Iranian intelligence.