CTIPilot

APT42

actor · actor:apt42

Iranian MOIS/IRGC-aligned espionage and social-engineering actor. Per Google GTIG (reported via Recorded Future/Insikt Group, 2026-07-16) it uses Gemini as an engineering platform to accelerate development of specialized malicious tools and feeds the model target biographies to script multi-turn rapport-building phishing conversations before payload delivery.

Aliases: GreenBravo, Charming Kitten, Mint Sandstorm, CALANQUE ION

Coverage timeline
0
first 2026-07-19 → last –
no data
Peak priority
·
no matching entries
Sources cited
0
0 hosts
Sections touched
0
·
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

No published entries reference this entity yet.

explore in graph

Entries about APT42

No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.