[APT42](https://attack.mitre.org/groups/G1044) has collected data from Microsoft 365 environments.(Citation: Mandiant APT42-untangling)(Citation: Mandiant APT42-charms)
[APT42](https://attack.mitre.org/groups/G1044) has used tools such as [NICECURL](https://attack.mitre.org/software/S1192) with command and control communication taking place over HTTPS.(Citation: Mandiant APT42-untangling)
[APT42](https://attack.mitre.org/groups/G1044) has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.(Citation: Mandiant APT42-untangling)(Citation: Mandiant APT42-charms)(Citation: TAG APT42)
Useful?
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
[APT42](https://attack.mitre.org/groups/G1044) has used tools such as [NICECURL](https://attack.mitre.org/software/S1192) with command and control communication taking place over HTTPS.(Citation: Mandiant APT42-untangling)
[APT42](https://attack.mitre.org/groups/G1044) has used custom malware to steal login and cookie data from common browsers.(Citation: Mandiant APT42-charms)
[APT42](https://attack.mitre.org/groups/G1044) has intercepted SMS-based one-time passwords and has set up two-factor authentication.(Citation: Mandiant APT42-charms) Additionally, [APT42](https://attack.mitre.org/groups/G1044) has used cloned or fake websites to capture MFA tokens.(Citation: Mandia
[APT42](https://attack.mitre.org/groups/G1044) has used the PowerShell-based POWERPOST script to collect local account names from the victim machine.(Citation: Mandiant APT42-charms)
[APT42](https://attack.mitre.org/groups/G1044) has used malware, such as GHAMBAR and POWERPOST, to collect network information.(Citation: Mandiant APT42-charms)
[APT42](https://attack.mitre.org/groups/G1044) has used malware, such as GHAMBAR and POWERPOST, to collect system information.(Citation: Mandiant APT42-charms)
[APT42](https://attack.mitre.org/groups/G1044) has used Windows Management Instrumentation (WMI) to check for anti-virus products.(Citation: Mandiant APT42-untangling)
[APT42](https://attack.mitre.org/groups/G1044) has used Windows Management Instrumentation (WMI) to query anti-virus products.(Citation: Mandiant APT42-untangling)
[APT42](https://attack.mitre.org/groups/G1044) has sent spearphishing emails containing malicious links.(Citation: Mandiant APT42-charms)(Citation: Mandiant APT42-untangling)(Citation: TAG APT42)
APT42 has leveraged LLMs to search for official emails to build target lists, and conduct reconnaissance on potential business partners.(Citation: GTIG AI Threat Tracker)
[APT42](https://attack.mitre.org/groups/G1044) has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection.(Citation: Mandiant APT42-untangling)
[APT42](https://attack.mitre.org/groups/G1044) has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment.(Citation: Mandiant APT42-charms)(Citation: Mandiant APT42-untangling)
[APT42](https://attack.mitre.org/groups/G1044) has registered domains, several of which masqueraded as news outlets and login services, for use in operations.(Citation: Mandiant APT42-charms)(Citation: TAG APT42)
[APT42](https://attack.mitre.org/groups/G1044) has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.(Citation: Mandiant APT42-charms)
[APT42](https://attack.mitre.org/groups/G1044) has deleted login notification emails and has cleared the Sent folder to cover their tracks.(Citation: Mandiant APT42-charms)
[APT42](https://attack.mitre.org/groups/G1044) has impersonated legitimate people in phishing emails to gain credentials.(Citation: Mandiant APT42-charms)(Citation: TAG APT42)
Associated software
2 linked · 2 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 2
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Charming Kitten / APT42's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 10 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002partialAnti-SpoofingT1566significantAnti-SpoofingT1566.002significantConditional AccessT1530minimalMultifactor AuthenticationT1530significantMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.002partialPasswordless AuthenticationT1539significantRole Based Access ControlT1059minimalRole Based Access ControlT1087minimalRole Based Access ControlT1530partialAntimalwareT1036significantAntimalwareT1059significantAntimalwareT1059.001significantAntimalwareT1566significantAnti-PhishingT1566significantAnti-PhishingT1566.002significantAntiSpamT1566significantAntiSpamT1566.002significantAudit SolutionsT1070.008partialAudit SolutionsT1530partialAudit SolutionsT1566.002partialInformation ProtectionT1070significant
detect · 16 techniques
Adaptive Application Control IntegrationT1036partialAdaptive Application Control IntegrationT1036.005partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002significantApp GovernanceT1087significantApp GovernanceT1566significantAdvanced Threat HuntingT1087significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1566.002significantDefender for Cloud AppsT1071minimalDefender for Cloud AppsT1530partialMicrosoft Defender for IdentityT1047minimalMicrosoft Defender for IdentityT1059minimal
respond · 7 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002partialAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.002significantIncident ResponseT1059minimalIncident ResponseT1530minimalIncident ResponseT1566minimalQuarantine PoliciesT1036significantQuarantine PoliciesT1530significantQuarantine PoliciesT1566significantQuarantine PoliciesT1566.002significantSafe AttachmentsT1566significantATT&CK Simulation TrainingT1539partialATT&CK Simulation Training
Countermeasures · D3FEND
Defensive techniques that counter Charming Kitten / APT42's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.