Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FireEye’s January 2019 reporting described APT39 as an espionage actor that combined phishing and vulnerable-server compromises with backdoors, credential-theft utilities, remote-administration methods, and data-archiving tools. FireEye said the activity it had tracked since November 2014 focused mainly on telecommunications and travel organizations, where access could help the operators monitor people and collect personal, customer, or proprietary information.

Who is APT39?

APT39 was the label FireEye used in its January 2019 account to bring together activity and methods the company said it had tracked since November 2014. FireEye assessed the actor as Iran-linked and described its activity as espionage focused on surveillance and information collection. Those are FireEye’s assessments as reported at the time, not independently established motives.

Later sources add attribution context, but they should not be read as claims made in the 2019 report. MITRE ATT&CK’s profile, version 3.2 and last modified July 31, 2026, describes APT39 as one of several names for cyber-espionage activity conducted through Rana Intelligence Computing Company on behalf of Iran’s Ministry of Intelligence and Security (MOIS) since at least 2014. In a September 17, 2020 announcement, the U.S. Treasury described Rana as a front company used by MOIS. The Department of Justice’s account of coordinated 2020 actions lists APT39, Chafer, Remexi, Cadelspy, and ITG07 as public names associated with the group.

Which organizations did the 2019 report say it targeted?

FireEye said APT39 mainly targeted telecommunications and travel organizations, with additional targeting of high-tech companies and government entities. It reported activity concentrated in the Middle East but extending globally, including to the United States and South Korea.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FireEye reasoned that telecommunications and travel records could help operators track or monitor particular people, as well as obtain personal, customer, or proprietary data. The report described this as an assessment of likely purpose; it did not establish that every targeted organization or intrusion served the same objective.

MITRE’s later profile describes a broader set of sectors and locations: travel, hospitality, academic, and telecommunications targets across Iran and regions of Asia, Africa, Europe, and North America. That profile is not the same snapshot as FireEye’s 2019 summary, so the two descriptions should be kept with their respective dates and sources.

How did APT39 get into networks and use its tools?

FireEye’s reported intrusion picture combined custom malware with publicly available software and legitimate administration methods. The tools below are examples of the reported tradecraft, not all unique to APT39; their presence alone does not prove attribution.

Initial access

FireEye reported spear-phishing messages with malicious attachments or links, often leading to POWBAT. It also described attacks on vulnerable web servers, including installation of web shells such as ANTAK and ASPXSPY, and theft of credentials to extend access. MITRE’s profile provides a maintained technique mapping and cites the FireEye report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Footholds, credentials, and reconnaissance

After compromise, the reported backdoors included SEAWEED, CACHEMONEY, and a distinct variant of POWBAT. Tools named for credential access or reconnaissance included Mimikatz, Ncrack, Windows Credential Editor, ProcDump, and the custom port scanner BLUETORCH.

Movement between systems and proxying

For lateral movement, FireEye reported use of RDP and SSH, as well as PsExec, RemCom, and xCmdSvc. It also said custom tools REDTRIP, PINKTRIP, and BLUETRIP created SOCKS5 proxies between infected hosts.

Preparing collected data

FireEye reported that stolen data was commonly compressed with WinRAR or 7-Zip. The account does not establish that these utilities were exclusive to the actor or specify one universal method for moving data out of victim networks.

What did U.S. authorities report in 2020?

The Treasury Department’s September 17, 2020 announcement provides a separate government account, not additional statistics from FireEye’s 2019 report. Treasury said it sanctioned APT39, 45 associated individuals, and Rana; described victims in hundreds of individuals and entities across more than 30 countries; and reported approximately 15 U.S. companies, primarily in the travel sector. Treasury also said the campaign targeted Iranian dissidents, journalists, international travel companies, and other perceived adversaries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These figures describe Treasury’s account of its 2020 sanctions action. They are not general estimates of APT39’s prevalence, total victim count, or activity across all years.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the reported tools do—and do not—show

  • They show a mix of methods. The account includes malware, web shells, credential and reconnaissance utilities, remote-administration methods, proxy tools, and archivers.
  • They do not make every tool an APT39-only indicator. Some were publicly available or legitimate administration tools. A name in the report is not, by itself, proof that an intrusion was conducted by APT39.
  • They do not establish a single end-to-end playbook. The described methods indicate how access, persistence, movement, and collection could fit together; the account does not say every operation used every listed tool.

How should organizations use this account defensively?

The reporting points to several areas worth reviewing, but it does not prescribe a particular product or prove that one control is best. A response should fit the organization’s scale, existing security tools, and whether the immediate need is to contain an incident or investigate activity over time.

  • For suspected active compromise: prioritize containment and incident response, including review of exposed web servers, suspicious web shells, compromised credentials, and unexpected remote access.
  • For investigation: correlate identity, email, endpoint, and web-server evidence; look for lateral movement and proxy activity rather than treating an individual tool name as conclusive attribution.
  • For longer-term monitoring: consider whether the organization can retain and analyze relevant logs and threat intelligence across the systems implicated by the reported access paths.

These are defensive considerations inferred from the reported methods, not a validated ranking of controls. Organizations without the staff or visibility to investigate across those systems may need incident-response or threat-intelligence support.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.