Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0087
MITRE ATT&CK Group

APT39 (G0087)

ITG07ChaferRemix Kitten
ShareXLinkedInRedditHN

[APT39](https://attack.mitre.org/groups/G0087) is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. [APT39](https://attack.mitre.org/groups/G0087) has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.(Citation: FireEye APT39 Jan 2019)(Citation: Symantec Chafer Dec 2015)(Citation: FBI FLASH APT39 September 2020)(Citation: Dept. of Treasury Iran Sanctions September 2020)(Citation: DOJ Iran Indictments September 2020)

▪Techniques used (53)

T1046Network Service DiscoveryT1547.001Registry Run Keys / Startup FolderT1090.002External ProxyT1140Deobfuscate/Decode Files or InformationT1056.001KeyloggingT1005Data from Local SystemT1059.001PowerShellT1115Clipboard DataT1003OS Credential DumpingT1553.006Code Signing Policy ModificationT1546.010AppInit DLLsT1547.009Shortcut ModificationT1135Network Share DiscoveryT1569.002Service ExecutionT1027.013Encrypted/Encoded FileT1588.002ToolT1021.001Remote Desktop ProtocolT1033System Owner/User DiscoveryT1027.002Software PackingT1041Exfiltration Over C2 ChannelT1204.002Malicious FileT1053.005Scheduled TaskT1070.004File DeletionT1102.002Bidirectional CommunicationT1560.001Archive via UtilityT1505.003Web ShellT1105Ingress Tool TransferT1059.010AutoHotKey & AutoITT1204.001Malicious LinkT1555Credentials from Password StoresT1113Screen CaptureT1003.001LSASS MemoryT1018Remote System DiscoveryT1071.004DNST1059Command and Scripting InterpreterT1074.001Local Data StagingT1083File and Directory DiscoveryT1012Query RegistryT1110Brute ForceT1197BITS JobsT1136.001Local AccountT1059.006PythonT1036.005Match Legitimate Resource Name or LocationT1071.001Web ProtocolsT1090.001Internal ProxyT1078Valid AccountsT1056Input CaptureT1566.002Spearphishing LinkT1566.001Spearphishing AttachmentT1021.002SMB/Windows Admin SharesT1190Exploit Public-Facing ApplicationT1059.005Visual BasicT1021.004SSH

▪Software used (11)

S0590NBTscantoolS0459MechaFloundermalwareS0375RemeximalwareS0488CrackMapExectoolS0006pwdumptoolS0002MimikatztoolS0005Windows Credential EditortoolS0454CadelspymalwareS0029PsExectoolS0073ASPXSpymalwareS0095ftptool
G0087on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.