TechForge

30th January 2019

Share this story:

Tags:

Categories::

Cybersecurity firm FireEye claims to have identified an Iranian hacking group which is attacking telcos around the world.

FireEye exposed the group called ‘APT39’ last month. APT39’s main goal appears to be stealing personal information.

According to FireEye, this goal makes APT39 somewhat unique. Other Iranian hacking groups tracked by the cybersecurity firm are linked to influence operations, disruptive attacks, and other threats.

In a blog post, FireEye wrote:

“APT39 likely focuses on personal information to support monitoring, tracking, or surveillance operations that serve Iran’s national priorities, or potentially to create additional accesses and vectors to facilitate future campaigns.”

APT39 primarily uses the backdoors known as ‘CACHEMONEY’ and ‘SEAWEED’ in addition to a variant of the ‘POWBAT’ backdoor.

The group focuses on targets in the Middle East but has been linked to countries elsewhere in the world. Perhaps to be expected, the US is among its targets.

FireEye has produced the following map showing countries APT39 is linked with:

fireeye

Considering APT39’s goal of collecting personal data and espionage, it’s of little surprise telcos are its main target. Others sectors targeted include the ‘high-tech’ and travel industries.

FireEye has ‘moderate confidence’ APT39 is working to advance Iranian state interests.

In a sheer coincidence, US intelligence officials unveiled their latest ‘Worldwide Threat Assessment’ today. The report states Iran continues to "present a cyber espionage and attack threat" to the US and its allies.

"Iran uses increasingly sophisticated cyber techniques to conduct espionage; it is also attempting to deploy cyberattack capabilities that would enable attacks against critical infrastructure in the United States and allied countries," the report warns.

Tensions between Iran and the US are strained over President Trump’s decision to withdraw from the Iran nuclear deal and reimpose sanctions. Given the breakdown in relations, it’s unlikely the cyber threat from Iran will cease anytime soon.

Last week, Iran-linked hackers took advantage of the US government’s record-long shutdown to launch a cyberattack.

Interested in hearing industry leaders discuss subjects like this and sharing their experiences? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London, and Amsterdam to learn more.

About the Author

Senior Editor

Ryan Daws is a senior editor at TechForge Media with over a decade of experience in crafting compelling narratives and making complex topics accessible. His articles and interviews with industry leaders have earned him recognition as a key influencer by organisations like Onalytica. Under his leadership, publications have been praised by analyst firms such as Forrester for their excellence and performance. Connect with him on X (@gadget_ry), Bluesky (@gadgetry.bsky.social), and/or Mastodon (@gadgetry@techhub.social)

Related

Aerospacelab wins European IRIS² satellite contract

11th September 2026

Eutelsat and Skynopy deploy Global AKAR satellite ground network

10th September 2026

AI agent libraries risk becoming telecom’s new OSS trap

9th September 2026

UK commits £7.8B to orbital assets and space strategy

8th September 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

Customer engagement and billing are vital to a CSP’s success

9032 view(s)

T-Mobile and Ericsson test AI-RAN on live 5G Advanced network

1499 view(s)

AST SpaceMobile targets beta D2D service with next BlueBird launch

1108 view(s)

Ericsson adds AI in RAN software for 5G network optimisation

1068 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.