APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
APT42 (aka UNC788, CALANQUE) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
APT42
G1044
APT
IR · Iran
AKA
UNC788 · CALANQUE · ITG18 · Yellow Garuda · Damselfly
CrowdStrike
:
Charming Kitten
Microsoft
:
Mint Sandstorm
MITRE
:
G1044
Proofpoint
:
TA453
Secureworks
:
IRON RITUAL
Targets
21
Sectors
15
Threat types
1
GIRs covered
0/480
Active since
2015
Pin to atlas
Watch
Share
Export
Also tracked as
6 vendor names · 5 other aliases
Open Rosetta Stone
CrowdStrike
Charming Kitten
Mandiant
APT42
Microsoft
Mint Sandstorm
MITRE
G1044
Proofpoint
TA453
Secureworks
IRON RITUAL
UNATTRIBUTED ALIASES
UNC788
CALANQUE
ITG18
Yellow Garuda
Damselfly
Victimology
Geographic footprint · 21 countries
Region filter
Export
origin · Iran
targeted countries · 21
ASIA ·
9
United Arab Emirates
·
Azerbaijan
·
Israel
·
Iraq
·
Iran
·
Lebanon
·
Malaysia
·
Saudi Arabia
·
Türkiye
EUROPE ·
9
Albania
·
Austria
·
Belgium
·
Bulgaria
·
Germany
·
United Kingdom
·
Italy
·
Norway
·
Ukraine
OCEANIA ·
1
Australia
AFRICA ·
1
Egypt
AMERICAS ·
1
United States
Sectors targeted
15 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Financial Services
74 actors
Healthcare
47 actors
Pharmaceutical
27 actors
Technology
60 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Oil and Gas
21 actors
Education & Research
62 actors
Manufacturing (man)
50 actors
Media & Journalism
49 actors
Legal & Professional
18 actors
Dissidents (as targets)
16 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 20 techniques
Reconnaissance
· 1
T1682
Query Public AI Services
Resource Development
· 1
T1583.003
Virtual Private Server
Initial Access
· 1
Execution
· 4
T1047
Windows Management Instrumentation
Persistence
· 1
T1547
Boot or Logon Autostart Execution
Credential Access
· 2
T1111
Multi-Factor Authentication Interception
Discovery
· 1
T1016
System Network Configuration Discovery
Collection
· 2
T1056
Input Capture
T1113
Screen Capture
Command And Control
· 3
T1071.001
Web Protocols
T1102
Web Service
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 3
T1036.005
Match Legitimate Resource Name or Location
T1070
Indicator Removal
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
20 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1566.002
Spearphishing Link
T1053.005
Scheduled Task
T1059.001
PowerShell
T1059.005
Visual Basic
T1555.003
Credentials from Web Browsers
T1573.002
Asymmetric Cryptography
T1684.001
Impersonation