# APT42

Type: organization

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/apt42
Canonical HTML page: https://getcyberbrief.com/entity/apt42

## Timeline

- **2026-03-12**: Coordinated Campaign — Widespread phishing campaign detected targeting state-level election officials and infrastructure administrators.
- **2026-03-07**: Global OT Alert — International cybersecurity agencies issue joint warning regarding vulnerabilities in ICS/SCADA systems.
- **2026-03-05**: Defense Contractor Phishing — Coordinated phishing campaign by APT33 targeting US and UK defense supply chains.
- **2026-03-03**: Wiper Malware Detected — First reports of destructive Azero-Wiper payloads in regional logistics hubs in the Middle East.
- **2026-03-01**: Conflict Commencement — Initial kinetic operations begin; first wave of DDoS attacks hits Iranian government portals.
- **2026-02-20**: CISA Joint Advisory — CISA and FBI issue a critical alert regarding APT42 targeting high-value individuals in the US defense industrial base.
- **2026-01-15**: Reconnaissance Surge — Significant uptick in scanning of US municipal water treatment facilities by IP addresses linked to Iranian infrastructure.

## Recent coverage (2 stories)

### Iranian Cyber Operations Escalate Against US Critical Infrastructure
2026-03-13 02:03:27 · Sentiment: Negative · Impact: 7/10 · Sources: 2

Iranian state-sponsored hacking groups are intensifying their focus on United States critical infrastructure, shifting from traditional espionage to potentially disruptive operations. This surge in activity coincides with heightened geopolitical tensions and a tactical pivot toward targeting operational technology and identity-based systems.
Full story: https://getcyberbrief.com/story/iran-linked-cyber-threats-us-infrastructure

### Global Cyber Fallout Intensifies One Week Into Iran Conflict
2026-03-07 13:30:25 · Sentiment: Negative · Impact: 9/10 · Sources: 2

One week after the commencement of kinetic operations involving Iran, the digital battlefield has expanded into a global 'gray zone' conflict. State-aligned threat actors have transitioned from espionage to destructive operations, targeting critical infrastructure and financial systems across the West and the Middle East.
Full story: https://getcyberbrief.com/story/iran-war-cyber-fallout-analysis

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.