A new Iranian-sponsored hacking group known as APT42 has been discovered that uses a custom Android malware to spy on targets of interest.

The cybersecurity firm has collected enough evidence to determine that the APT42 group is an Iran-backed threat actor engaged in cyberespionage against individuals and organizations of particular interest to the Iranian government.
See also: HP: Fixes bug in pre-installed Support Assistant tool
The first signs of APT42 activity date back seven years and revolve around long-running spear-phishing targeting government officials, politicians, journalists, academics around the world, and Iranian dissidents.
Hackers' goal is to steal account credentials. However, in many cases, they also develop a customized strain of Android malware with the ability to track victims, access device storage, and extract communication data.
Campaigns and goals
According to Mandiant, which discovered APT42's activities, the group has carried out at least 30 operations in 14 countries since 2015.

The group has changed targets several times to suit changing intelligence gathering interests. For example, in 2020, APT42 used phishing emails impersonating an Oxford University vaccinologist to target foreign pharmaceutical products.

In 2021, the APT42 group used compromised email addresses from US media organizations to target victims with fake interview, interacting with them for 37 days before hitting them with a credential harvesting page.

Most recently, in February 2022, hackers impersonated a British news agency to target political science in Belgium and the United Arab Emirates.
In most cases, hackers aimed to collect credentials by directing their victims to phishing pages designed to appear as legitimate login portals.
See also: North Face: 200,000 accounts compromised through credential stuffing
They do this either by sending shortened links or an attached PDF containing buttons that lead to credential collection pages that can also steal MFA codes.

Android malware
The mobile malware strain used in APT42 campaigns helps the threat actor closely monitor its most high-interest targets (phone calls, incoming SMS, and more).
Mandiant says the Android spyware is primarily spread to Iranian targets via SMS messages containing links to a messaging app or VPN that can help bypass government-imposed restrictions.

However, Mandiant says it is also discovering landing pages for downloading IM apps in Arabic, so the threat actors may have developed the Android malware outside of Iran as well.
The APT42 group uses a rich set of lightweight custom malware on Windows systems to establish a base and steal credentials that will allow them to escalate privileges and conduct network.
See also: Albania blames Iran for July cyberattack and breaks diplomatic relations
For lateral movement, hackers send phishing emails to colleagues of the compromised user. At the same time, presence on newly compromised is ensured by adding scheduled tasks and new Windows registry keys.

Links to ransomware
Mandiant highlights the connection between APT42 group TTPs and ransomware using BitLocker ,reported in November 2021 by Microsoft.
Mandiant now says there is sufficient technical evidence to link the APT42 attacks, along with the APT35 group.
Finally, Mandiant estimated (with all reservations) that APT42 and APT35 are both operations of the IRGC (Islamic Revolutionary Guard Corps), which the US designates as a terrorist organization.
Information source: bleepingcomputer.com
