Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1044
MITRE ATT&CK Group

APT42 (G1044)

ShareXLinkedInRedditHN

[APT42](https://attack.mitre.org/groups/G1044) is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.(Citation: Mandiant APT42-charms) The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.(Citation: Mandiant APT42-charms) [APT42](https://attack.mitre.org/groups/G1044) starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices.(Citation: Mandiant APT42-charms) Finally, [APT42](https://attack.mitre.org/groups/G1044) exfiltrates data using native features and open-source tools.(Citation: Mandiant APT42-untangling) [APT42](https://attack.mitre.org/groups/G1044) activities have been linked to [Magic Hound](https://attack.mitre.org/groups/G0059) by other commercial vendors. While there are behavior and software overlaps between [Magic Hound](https://attack.mitre.org/groups/G0059) and [APT42](https://attack.mitre.org/groups/G1044), they appear to be distinct entities and are tracked as separate entities by their originating vendor.

▪Techniques used (32)

T1059.001PowerShellT1518.001Security Software DiscoveryT1036.005Match Legitimate Resource Name or LocationT1070Indicator RemovalT1056Input CaptureT1583.001DomainsT1132.001Standard EncodingT1530Data from Cloud StorageT1059.005Visual BasicT1113Screen CaptureT1684.001ImpersonationT1016System Network Configuration DiscoveryT1087.001Local AccountT1585.002Email AccountsT1053.005Scheduled TaskT1682Query Public AI ServicesT1070.008Clear Mailbox DataT1056.001KeyloggingT1102Web ServiceT1082System Information DiscoveryT1071.001Web ProtocolsT1583.003Virtual Private ServerT1573.002Asymmetric CryptographyT1047Windows Management InstrumentationT1539Steal Web Session CookieT1608.001Upload MalwareT1588.002ToolT1111Multi-Factor Authentication InterceptionT1547Boot or Logon Autostart ExecutionT1112Modify RegistryT1566.002Spearphishing LinkT1555.003Credentials from Web Browsers

▪Software used (2)

S1192NICECURLmalwareS1193TAMECATmalware
G1044on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.