APT42: Crooked Charms, Cons and Compromises
released on 2022-09-07 @ 05:47:19 PM
Active since at least 2015, APT42 is characterized by highly targeted spear phishing and surveillance
operations against individuals and organizations of strategic interest to Iran. The group’s operations,
which are designed to build trust and rapport with their victims, have included accessing the personal and
corporate email accounts of government officials, former Iranian policymakers or political figures, members
of the Iranian diaspora and opposition groups, journalists, and academics who are involved in research on Iran.
After gaining access, the group has deployed mobile malware capable of tracking victim locations, recording
phone conversations, accessing videos and images, and extracting entire SMS inboxes.