
A state-sponsored advanced persistent threat (APT) actor recently christened APT42 (formerly UNC788) has been attributed to over 30 confirmed espionage attacks against individuals and organizations of strategic interest to the Iranian government a minimum of since 2015. Cybersecurity firm Mandiant same the cluster operates because the intelligence gathering arm of Iran's islamic Revolutionary Guard Corps (IRGC), to not mention shares partial overlaps with another cluster referred to as APT35, that is additionally called Charming Kitten, cobalt Illusion, ITG18, Phosphorus, TA453, and Yellow Garuda. APT42 has exhibited a propensity to strike numerous industries like non-profits, education, governments, healthcare, legal, producing, media, and pharmaceuticals spanning a minimum of 14 countries, as well as in Australia, Europe, 30 East, and the U.S.
