APT39 (Chafer) is an Iranian MOIS cyber-espionage group, operated through the Rana Intelligence Computing front company, that specializes in personal-information collection and individual tracking — targeting telecommunications, travel, and hospitality organizations across Iran and the wider Middle East to monitor persons of interest to Iranian intelligence.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
APT39 was designated by FireEye/Mandiant in January 2019 and formally exposed in September 2020 when the U.S. Treasury sanctioned Rana Intelligence Computing as an MOIS front and the FBI issued a FLASH on the group, unmasking associated individuals and tooling. MITRE tracks it as G0087; Symantec separately documented overlapping activity as Chafer from 2015. Attribution to MOIS is high confidence given the sanctions and indictment record.
+82 more relationships — see the relationships browser.
The group's distinguishing mission is surveillance of individuals rather than intellectual-property theft. It favors spearphishing with malicious attachments/links, exploitation of internet-facing services and web shells, and a custom/commodity toolset including the SEAWEED and CACHEMONEY backdoors and variants of POWBAT, plus extensive use of stolen credentials, RDP, and legitimate admin tools for lateral movement. Its heavy telecom and travel targeting supports tracking the movements and communications of dissidents, journalists, and other persons of interest.
MENA is a core theater. Alongside domestic Iranian targeting, APT39 hit telecommunications and travel/hospitality firms across the Middle East (and further afield in Asia, Africa, Europe, and North America), using these sectors as data-rich chokepoints for identifying and monitoring targets.
Following the 2020 U.S. sanctions and indictments, distinct APT39/Chafer-branded activity declined markedly and the group is assessed as dormant under this name, though MOIS individual-surveillance missions continue through successor and sibling clusters. It is retained here as a key MOIS historical entry.