LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.CitationFireEye APT39 Jan 2019CitationSymantec Chafer Dec 2015CitationFBI FLASH APT39 September 2020CitationDept. of Treasury Iran Sanctions September 2020CitationDOJ Iran Indictments September 2020

EnterpriseG0087GroupObject v3.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

APT39 matters because MITRE describes it as long-running espionage activity tied to MOIS through Rana Intelligence Computing, with targeting of travel, hospitality, academic, and telecommunications organizations across multiple regions. For leaders, the practical issue is not just malware names; it is whether the organization can detect credential theft, lateral movement, remote access, web shells, internal discovery, and data collection before sensitive personal or operational information leaves the environment.

Executive priority

Prioritize this as an identity, data-protection, and incident-readiness use case, especially if the organization operates in or supports travel, hospitality, academia, telecommunications, or high-risk regions named by MITRE. Executives should ask whether SOC coverage can prove visibility into credential dumping, remote administration abuse, internal reconnaissance, and exfiltration paths, and whether IR teams can rapidly scope compromised accounts and systems. This object also supports audit and compliance discussions around privileged access control, logging completeness, and evidence of monitoring for data access and outbound transfer.

Technical view

ATT&CK provides no official detection text and no group-level platforms or tactics, so validation should be relationship-driven. The related software and techniques point to a Windows-heavy credential and lateral-movement pattern, including Mimikatz, Windows Credential Editor, pwdump, CrackMapExec, PsExec, RDP, SMB/admin shares, LSASS memory access, registry queries, user and remote system discovery, web shell activity via ASPXSpy, FTP transfer, RAT/backdoor tools such as Remexi, Cadelspy, and MechaFlounder, and exfiltration over a C2 channel. SOC and IR teams should test whether endpoint, identity, network, and server logs can connect these behaviors into one intrusion narrative rather than isolated alerts.

Likely telemetry

  • Windows endpoint telemetry for process creation, suspicious credential access, LSASS memory access, registry queries, service creation, and execution from unusual paths
  • Authentication and identity logs for unusual privileged logons, RDP sessions, SMB/admin share access, and SSH where applicable
  • Network telemetry for internal host discovery, SMB/RDP/SSH activity, FTP use, outbound C2-like communications, and anomalous data transfer
  • Web server logs and file integrity evidence for possible ASPX web shell placement or execution
  • File and malware telemetry for packed, encrypted, encoded, or masqueraded executables and scripts

Detection direction

  • Validate detections for credential dumping and LSASS access, including use of known tools such as Mimikatz, Windows Credential Editor, and pwdump, while accounting for authorized security testing noise.
  • Correlate discovery commands and behaviors, such as remote system discovery, user discovery, registry queries, and NBTscan-like activity, with subsequent authentication or lateral movement.
  • Baseline legitimate RDP, SMB/admin share, SSH, PsExec, and FTP usage; these are dual-use paths and require context such as source host, account privilege, time, destination, and change-ticket evidence.
  • Review web-facing Windows servers for web shell indicators and suspicious ASPX activity, especially where ASPXSpy-like behavior would be possible.
  • Tune for obfuscation blind spots: packed, encrypted, encoded, or legitimately named files may reduce signature-only detection value.

Mitigation priorities

  • Start with privileged access hygiene: reduce standing admin rights, separate admin accounts, enforce strong authentication for remote access, and monitor privileged credential use.
  • Restrict and monitor lateral movement paths such as RDP, SMB/admin shares, SSH, and remote execution tools; allow only documented administrative workflows.
  • Harden systems that can host web shells, especially externally reachable web servers, and maintain change control over web directories and server-side scripts.
  • Improve endpoint hardening and logging around credential material, process access, suspicious tooling, and execution from trusted-looking paths.
  • Apply network egress controls and monitoring for FTP, unusual outbound sessions, and potential C2-channel data transfer.
Additional notes and limits

The strongest decision value comes from combining the group description with the listed relationships. APT39 is described by MITRE as espionage activity focused on tracking individuals and entities, and the related techniques/software emphasize credential access, discovery, lateral movement, remote access, web shells, obfuscation, collection, and exfiltration. Treat this as a coverage assessment for identity-centric intrusion response rather than a single malware detection problem.

MITRE provides no official detection guidance and no group-level platforms or tactics for this object. Related software and techniques identify behaviors to validate, but they do not prove those tools or techniques are present in any specific environment. Local asset exposure, sector relevance, authentication patterns, and logging completeness are required to assess risk and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.CitationFireEye APT39 Jan 2019CitationSymantec Chafer Dec 2015CitationFBI FLASH APT39 September 2020CitationDept. of Treasury Iran Sanctions September 2020CitationDOJ Iran Indictments September 2020

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.2
Created
Modified
Raw hash
cdee270d3cad1eb4...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.