FlagThis
← Threat Actors
/
Iran
/
APT42
DOSSIER // APT42
APT42
ACTIVE CAMPAIGN TRACKED
▲ High Threat
Iran
Primary Aliases:
UNC788
CALANQUE
CALANQUE ION
G1044
🔍 Adversary Rosetta Stone (5) ▾
📋 Copy All
Sponsor / State Affiliation
Islamic Republic of Iran
Primary Motivation
Political and strategic espionage
Active Timeline
Unknown – Present
Confidence Rating
95% (Grounded)
Google Account Social Engineering Campaign, Regional Diplomatic Espionage
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Government agencies
Diplomatic missions
Journalists
Academic researchers
Human rights activists
Iranian dissidents
🛡️ MITRE ATT&CK® Attack Lifecycle
(8 TTPs)
📥 Download Navigator JSON
All Stages
8
Initial Access
1
Persistence & Privilege Escalation
2
Credential Access & Discovery
2
Command & Control
2
Operational Techniques
1
Initial Access
1
T1566
Spear-phishing
↗
Persistence & Privilege Escalation
2
T1547
Session Hijacking (Cookie Theft)
↗
T1547
OAuth Token Abuse
↗
Credential Access & Discovery
2
T1003
Advanced Social Engineering
↗
T1003
Credential Harvesting
↗
Command & Control
2
T1071
Use of legitimate cloud services for C2
↗
T1071
Custom malware delivery
↗
Operational Techniques
1
T1000
MFA Bypass techniques
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Iranian APT42 and APT35 Utilizing LLMs for AI-Augmented Spear-Phishing and Tamecat Malware Deployment
Attacks and Vulnerabilities
2026-08-15
Adversary Rosetta Stone // APT42
×
🔍 Mandiant / Google Threat Intel
UNC788
📋
🛡️ Other Industry Tracking Codes
CALANQUE
📋
CALANQUE ION
📋
G1044
📋
GreenBravo
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD