APT42
1 incidentes
0 paises
1 sectores
apt IR Ultimo: 2026-05-25
Aliases: CALANQUE, UNC788, APT 42
APT42 is an Iranian state-sponsored cyber espionage group, assessed with moderate confidence to operate on behalf of the Islamic Revolutionary Guard Corps (IRGC) Intelligence Organization. Active since at least 2015, the group's primary motivation is intelligence gathering and surveillance in support of Iran's strategic geopolitical and security objectives, rather than financial gain or disruption. APT42 uniquely distinguishes itself through its exceptionally patient and persistent social engineering tactics, often engaging targets in trust-building conversations for days or weeks before attempting to deliver malicious content. The group is known by various aliases including UNC788, CALANQUE, and Charming Kitten, and is distinct from other Iranian actors by its consistent focus on targeting individuals and organizations perceived as opponents or enemies of the Iranian regime, particularly through credential harvesting and mobile surveillance, with a preference for cloud environments.