← Back to all threat actors

APT39

Also known as ITG07, Chafer, Remix Kitten
Tracked as G0087

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.

How we source and review actor profiles
Motivation
nation-state
Sectors
telecom, government, research-academia
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: ITG07

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Chafer

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Remix Kitten

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0087

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT39Canonical Name
ChaferAlias
ITG07Alias
Remix KittenAlias
G0087Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...