Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Iran-linked cyber operations can persist for years, but that does not mean one attacker remains continuously inside one network for that entire period. Mandiant says a suspected counterintelligence operation began as early as 2017 and lasted at least until March 2024, using more than 35 fake recruiting websites to gather information. Other reporting documents the same broader pattern of trust-building phishing, credential theft, cloud access and changing malware—including Microsoft’s 2024 reporting on the Tickler backdoor.

What does “long-running” mean in Iranian cyber operations?

It describes the duration of an operation or intelligence objective, not necessarily uninterrupted access to a particular victim’s network. Mandiant’s timeline covers a suspected counterintelligence operation from as early as 2017 through at least March 2024. The report describes a network of more than 35 fake recruiting websites used to collect personal, professional and academic information.

Such sites can support reconnaissance and social engineering: information supplied by a target may help an operator tailor later contact or impersonate a credible recruiter or institution. The reporting does not establish that every person who encountered a site was compromised, or that any single victim network remained accessible throughout the entire 2017–2024 period.

Operationally, persistence can mean returning to an intelligence objective after defenders block one route. Operators may harvest credentials, impersonate trusted contacts, seek access to cloud services and replace malware or infrastructure when existing tools are detected. The objective can endure while the methods change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who is APT42, and how does its approach work?

APT42 is the name used in Mandiant reporting for an Iran-nexus threat actor associated with counterintelligence and social-engineering operations. Mandiant describes the group using trust-building approaches to gain access to victims, including cloud environments. The label identifies a reported activity cluster; it should not be treated as proof that every Iran-linked incident belongs to this group.

Recruiting and professional lures

Mandiant observed more than 35 fake recruiting websites with Farsi decoy content and Israel-related imagery. Visitors were asked for personal and professional details. An unexpected job, research or conference invitation can therefore be useful to an operator even if it does not immediately deliver malware: a target’s information may enable more convincing follow-up contact.

Credential and cloud access

Social engineering can be aimed at obtaining credentials or persuading a target to interact with a false sign-in or document-sharing flow. Stolen or misused credentials can provide a path into email and cloud services, where access may be less visible than a familiar malware infection. Mandiant’s reporting identifies cloud environments as part of the access picture, but does not establish that every campaign uses the same sequence.

Who is targeted, and why do targets vary?

Reported targets align with several overlapping intelligence and geopolitical interests. They include dissidents and activists, government and intergovernmental organizations, Israeli companies, and people in policy or political circles. Campaigns may support counterintelligence against people perceived to be cooperating with foreign services, espionage against institutions or technology targets, or activity related to regional conflict and influence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft reported that nearly half of the Iranian operations it observed from October 7, 2023, to July 2024 targeted Israeli companies. That figure describes Microsoft’s observed operations during that stated period; it is not a measure of all Iranian cyber activity or of the share of all Israeli organizations attacked.

What is Tickler malware, and what does it show?

Tickler is a custom, multi-stage backdoor that Microsoft reported Peach Sandstorm used between April and July 2024. A backdoor can give an operator a means to execute follow-on activity after access is established; “multi-stage” indicates the reported tool operates through multiple components or steps. Microsoft’s observation is evidence of a changing toolkit, not proof that Tickler was used in the separate APT42 campaign described by Mandiant.

Mandiant’s M-Trends 2025 report says Iran-nexus custom malware increased 35% compared with 2023 and that more than 45 new malware families were discovered in 2024. These are report-specific findings about custom malware and discovered families, not a count of all Iranian operations or a prediction that every target will encounter a new tool.

How can organizations defend against Iranian state-sponsored phishing?

Make stolen passwords less useful

  • Require phishing-resistant multifactor authentication (MFA), prioritizing FIDO2 security keys or certificate-based authentication for privileged accounts. Mandiant identifies these controls as recommended protections.
  • Review privileged accounts and authentication methods so that administrator access does not depend on a password plus a phishable approval prompt.

Reduce easy entry points

  • Patch internet-facing systems promptly and track whether critical updates have actually been installed.
  • Replace default and common passwords on connected devices and accounts. A June 2025 joint NSA, CISA, FBI and DC3 advisory warns that Iranian actors have historically targeted poorly secured U.S. networks and internet-connected devices for disruptive attacks.

Prepare to spot access that uses legitimate services

  • Maintain visibility into cloud activity and retain the data needed for threat hunting, such as authentication and administrative events.
  • Ensure incident-response procedures cover suspected stolen credentials and cloud accounts, not only malware on endpoints.
  • Investigate unusual access or account behavior in context, including activity involving privileged identities and unexpected authentication patterns.

Verify unusual invitations independently

Treat unexpected recruiting, research, conference or document-sharing invitations as possible reconnaissance or phishing attempts. Verify the sender through a separate, known channel rather than replying to the invitation or relying on contact details it provides. This is a practical precaution based on the documented fake-recruiting and impersonation methods, not an indication that every unsolicited invitation is malicious.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should reports about Iranian groups be compared?

Actor names and campaign reports describe different slices of activity. Mandiant’s APT42 reporting and Microsoft’s Peach Sandstorm reporting should not be collapsed into one group or one continuous campaign. Compare reports by the evidence they actually describe:

Reporting Mission or focus described Access or tooling detail Timeframe and scope
Mandiant on suspected counterintelligence operations Collection of personal, professional and academic information through recruiting-themed lures More than 35 fake recruiting websites; Farsi decoy content and Israel-related imagery As early as 2017 through at least March 2024
Mandiant on APT42 Trust-building social engineering to gain access, including to cloud environments Social engineering and credential-oriented access methods Specific campaign dates and a single universal duration are not stated here
Microsoft on Peach Sandstorm and Tickler Iran-nexus activity with a custom backdoor Tickler, a custom multi-stage backdoor Observed between April and July 2024
Microsoft’s observed Iranian operations Operations concentrated in part on Israeli companies Targeting statistic, not a single tool or group attribution Nearly half targeted Israeli companies from October 7, 2023, to July 2024

For defenders, the practical comparison is which part of the chain a control interrupts: phishing-resistant authentication limits the value of stolen passwords; patching and password hygiene reduce exposed entry points; and cloud logging helps investigators detect and contain access that uses legitimate accounts.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.