ICNA

Iranian Cyber News Agency

APT Iran

Affiliation:

Iran APT appears to be a pro-Iran and pro-regime hacktivist group, though exhibiting a notable shift in allegiance. Originally identified as “APT Iran Research Center” or «مرکز تحقیقات APT IRAN» and appearing anti-regime in early 2024, the group now openly supports Iranian interests as of 2026.

List of names used by the industry:

  • APT Iran
  • APT Iran Research Center
  • مرکز تحقیقات APT IRAN

Date founded:

Unconfirmed. The group appeared to be active as APT Iran Research Center as early as 2024, but rebranded in 2026 to APT Iran.


Social media handles:

Current Telegram: (created on March 2, 2026) @APTIRAN_OFFICIAL

Former Telegram: @APT_IRAN

qTox: 14ED2EAF412F7BF58756645E3E7406360A6B2080E429B74010431E594CC49F6B8ACA1189E4A6

Previous Operations:

2024 (as APT Iran Research Center – anti-regime focus):

March 3: Cyber-attack on Chargun Administrative Software (Iranian software company specializing in Enterprise Resource Planning solutions, particularly for administrative and financial management.

March 19: The group published images claiming infiltration of the Information Technology Unit of the National Registration Organization of Iran.

March 22: Claimed hack on Iranian railway infrastructure, alleging server disablements and client logouts, although verification appeared to be limited. The group claimed to have infiltrated the cyber infrastructure of Iran’s Railway Company in the attack on government networks, with documents revealing mandates for female employees to wear Islamic attire. Among the leaked documents was a directive signed by Mohsen Tabatabaei Atabak, the Director General of Planning and Monitoring of Passenger Services, outlining guidelines for employee conduct, including adherence to mandatory hijab for female staff.

The guidelines specify attire requirements, emphasizing “loose and long garments made of thick fabrics” and complete hair coverage.

The hackers also exposed identity documents, internal reports, and wagon maps.

March 27: The group’s channel was reportedly banned for sharing confidential content, suggesting conflict with regime elements.

2025 (Evolution – pro-regime focus):

June 13: The group claim to have accessed Israeli systems and leaked data belonging to 350,000 people.

June 14: The group claim on critical Israeli servers through the use of ALPHV and LockBit ransomware.

June 27: The group claim to infiltrate AT&T.

2026

February 3: APT Iran linked to a possible OT compromise in Israel.

March 2: Claimed cyber-sabotage targeting Jordan’s critical infrastructure, specifically the Jordanian Silos and Supply General Company. Targeted phishing led to SCADA system compromise managing temperature, moisture and weighing scales.

March 10: The group claimed access to a water treatment and utility management system (Mupferle Water Soluctions/Fenton).

March 18: Announced planned escalation in cyber-enabled surveillance and enforcement activities.

March 23: The group claimed a breach of LockHeed Martin systems, exfiltrating 375GB of data (F-35 Block 4 documentation, missile defense architechture, Pentagon contacts, employee data), demanding $400 million ransom.

August 4: Claimed complete wipe of postware.pro infrastructure, with customer data including contacts, Whatsapp conversations, and management data for sale on ThreatMarket.

August 8: Announced wiper attack on Turkish Yesilbeyaz Hosting (vpns.yesilbelyazhosting.com), claiming full disk wipe and data for sale.

August 23: The group declared they were not responsible for recent attacks against Britain, referencing the British power plant attack.

August 24: The group posted on their Telegram channel claiming they had been emailed by Nariman Gharib, Britain-based activist and cyber espionage investigator, and stated that he gets paid between 1 and 3 million dollars for every attack on UK critical infrastructure.

September 2: Threatened “unexpected and critical events” in U.S. telecom networks and energy infrastructure.

September 5: The group posted a “Message to the United States and the American People.”

September 9: The group claimed responsibility for disruptions to AT&T internet servers in Texas (San Antonio, Houston, Dallas, and Austin). They posted a video of the hack on their channel.

Shift in Allegiance: The group’s initial operations in 2024 as “APT Iran Research Center” strongly pointed towards a stand towards the Iranian regime, targeting domestic infrastructure and organizations. Over the following two years, coinciding with a possible rebranding to just “APT Iran”, the group’s focus shifted to international targets, with messaging and operations increasing aligning with Iranian geopolitical interests.

Tactics/Techniques/Tradecraft/Procedures (TTP’s):

  • Phishing: Targeted phishing attacks to gain initial foothold, as seen with the Jordan Silos breach.
  • RDP Access: Exploitation of Remote Desktop Protocol (RDP) for access and data infiltration.
  • Wiper Attacks: Deployment of wiper malware to erase data from compromised systems (Yesilbeyaz Hosting).
  • Ransomware Deployment: Utilizing LockBit Black ransomware samples to encrypt files (partial).
  • Data Exfiltration: Exfiltrating large volumes of sensitive data (LockHeed Martin hack).
  • Data Wiping and Extortion: Completely wiping systems and making data for sale/demanding ransom for stolen data.
  • Service Disruption: Causing disruption to critical services (railway, water treatment, internet).

Sources:

www.cybersecuritydive.com/news/lockheed-martin-breach-pro-iran-hacktivist/815430/

www.cybersecurity-insiders.com/apt-iran-hackers-steal-over-375tb-of-data-from-lockheed-martine/

www.cybernews.com/security/iran-takes-credit-for-at-t-outage

www.iranintl.com/en/202403246859

www.unit42.paloaltonetworks.com/iranian-cyberattacks-2026

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *