Threat Intelligence / Actor / APT42
APT42
As of 2026-07-16, APT42 is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat actor, vulnerability, apt. Also known as GreenBravo. ATT&CK coverage spans 72 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1059 (Command and Scripting Interpreter).
Also known as: GreenBravo
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Execution — observed in 3 of 3 tracked threats
- T1071 Application Layer Protocol — Command and Control — observed in 3 of 3 tracked threats
- T1082 System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Control — observed in 3 of 3 tracked threats
- T1566 Phishing — Initial Access — observed in 3 of 3 tracked threats
- T1003 OS Credential Dumping — Credential Access — observed in 2 of 3 tracked threats
- T1005 Data from Local System — Collection — observed in 2 of 3 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 2 of 3 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- T1053 Scheduled Task/Job — Persistence — observed in 2 of 3 tracked threats
- T1189 Drive-by Compromise — Initial Access — observed in 2 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Access — observed in 2 of 3 tracked threats
- T1204 User Execution — Execution — observed in 2 of 3 tracked threats
Tracked threats
- Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military Operations (2026 Conflict) — HIGH
- BlueHammer & RedSun: Windows Defender CVE-2026-33825 Zero-Day Remote Code Execution — CRITICAL
- APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting — CRITICAL
Related CVEs
CVE-2026-33825, CVE-2024-23897, CVE-2024-21893, CVE-2024-21887, CVE-2024-1709, CVE-2024-1708, CVE-2023-7028, CVE-2023-22527, CVE-2021-22205, CVE-2019-18935, CVE-2017-3506, CVE-2017-11317, CVE-2012-1823
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →