Threat Intelligence / Actor / APT42

APT42

As of 2026-07-16, APT42 is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat actor, vulnerability, apt. Also known as GreenBravo. ATT&CK coverage spans 72 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1059 (Command and Scripting Interpreter).

Nation: Iran · 3 tracked threat(s) · Categories: THREAT_ACTOR, VULNERABILITY, APT

Also known as: GreenBravo

ATT&CK techniques observed

72 techniques observed across 3 of 3 tracked threats · Command and Control (8), Persistence (8), Stealth (formerly Defense Evasion) (8), Discovery (7), Reconnaissance (7), Initial Access (6)

Tracked threats

Related CVEs

13 CVEs referenced by tracked APT42 activity

CVE-2026-33825, CVE-2024-23897, CVE-2024-21893, CVE-2024-21887, CVE-2024-1709, CVE-2024-1708, CVE-2023-7028, CVE-2023-22527, CVE-2021-22205, CVE-2019-18935, CVE-2017-3506, CVE-2017-11317, CVE-2012-1823

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence