53
Techniques
11
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.

View MITRE record ↗

Techniques by Tactic (53)
Resource Development
Toolsets (11)
🐛
ASPXSpy S0073
Malware · Windows
🐛
Cadelspy S0454
Malware · Windows
🐛
Malware · Windows
🐛
Remexi S0375
Malware · Windows
🔧
Tool · Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
NBTscan S0590
Tool · Windows, Linux, macOS
🔧
PsExec S0029
Tool · Windows
🔧
Tool · Windows
🔧
ftp S0095
Tool · Linux, Windows, macOS
🔧
pwdump S0006
Tool · Windows
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
↑