Penetration testing
Essential Eight
Resources
Intelligence
About
Contact
Request a quote
Home
›
Nations
›
🇮🇷 Iran
🇮🇷 Iran
19 Groups
Threat actors attributed to Iran based on public reporting and intelligence analysis.
Tactic Coverage
Tactics observed across Iran groups
Resource Development
17
Stealth
16
Initial Access
16
Collection
16
Persistence
14
Credential Access
14
Execution
14
Discovery
12
Privilege Escalation
12
Command & Control
12
Most Used Toolsets
Frequency of use across Iran groups
Mimikatz
8
PsExec
7
LaZagne
4
Net
3
Empire
3
ftp
3
DEADWOOD
2
ASPXSpy
2
🇮🇷 Iran Groups
G0059
Magic Hound
TA453, COBALT ILLUSION, Charming Kitten
78 techniques
13 software
G0049
OilRig
COBALT GYPSY, IRN2, APT34
76 techniques
30 software
G0069
MuddyWater
Earth Vetala, MERCURY, Static Kitten
68 techniques
21 software
G1055
VOID MANTICORE
COBALT MYSTIQUE, Handala Hack, Homeland Justice
63 techniques
0 software
G0087
APT39
ITG07, Chafer, Remix Kitten
53 techniques
11 software
G0117
Fox Kitten
UNC757, Parisite, Pioneer Kitten
41 techniques
5 software
G1044
APT42
32 techniques
2 software
G0064
APT33
HOLMIUM, Elfin, Peach Sandstorm
31 techniques
16 software
G1030
Agrius
Pink Sandstorm, AMERICIUM, Agonizing Serpens
22 techniques
9 software
G1012
CURIUM
Crimson Sandstorm, TA456, Tortoise Shell
19 techniques
1 software
G0077
Leafminer
Raspite
17 techniques
4 software
G0122
Silent Librarian
TA407, COBALT DICKENS
13 techniques
0 software
G1009
Moses Staff
DEV-0500, Marigold Sandstorm
12 techniques
4 software
G0052
CopyKittens
8 techniques
4 software
G1005
POLONIUM
Plaid Rain
7 techniques
2 software
G0130
Ajax Security Team
Operation Woolen-Goldfish, AjaxTM, Rocket Kitten
6 techniques
2 software
G0137
Ferocious Kitten
6 techniques
2 software
G0003
Cleaver
Threat Group 2889, TG-2889
5 techniques
4 software
G0043
Group5
4 techniques
2 software
↑