Threat Actor
APT42
- First Reported
- Mar 4, 2026
- Latest Reported
- Sep 8, 2026
Reported Context (3)
- Name the report says CALANQUE ION was previously tracked as. Google Reports Threat Actors Using AI for Automated Attacks and Credential Theft
- Described as IRGC-IO-linked and engaged in high-trust social engineering and cloud collection; operations targeted journalists, researchers, NGOs, academics, activists, and government-linked individuals. Midyear Assessment Finds Iran-Linked Cyber Risk Centered on Persistent Access and Trusted Pathways
- Explicitly also known as Charming Cypress or Mint Sandstorm. Tracked with 54 IPs, 233 hosts, and 44 SHA-256 hashes; recent activity involved TameCat targeting senior defense and government officials. Hunt.io Maps Infrastructure Linked to Iranian-Aligned Threat Actors
Malware (12)
People (1)
Threat Actors (53)
MITRE ATT&CK (11)
Vendors (13)
Products (30)
Tools (10)
Industries (20)
Countries (11)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.