CSIDB logo
Threat actor

NEPTUNIUM

Attribution profile

Type
Nation State
Location
Iran
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-16 03:11
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

NEPTUNIUM is an Iranian state‑sponsored threat actor tracked by Microsoft under the alias NEPTUNIUM. Public reporting also references the group as APT35 and Phosphorus. The actor is associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) and operates from within Iran.

NEPTUNIUM primarily targets organizations in the aerospace, defense, governmental, and energy sectors, with a focus on entities located in the United States, Europe, and the Middle East. Its observed objectives center on intelligence collection and espionage, seeking to acquire technical, military, and policy information. The group frequently conducts credential‑harvesting operations to establish persistent access within victim networks.

NEPTUNIUM’s typical tactics include spear‑phishing emails that contain malicious links or attachments designed to deliver PowerShell‑based downloaders and reconnaissance tools. It has been observed compromising legitimate websites to host credential‑phishing pages, a technique highlighted in the SpoofedScholars campaign. The actor employs both custom and publicly available malware for data exfiltration, often using HTTP and DNS channels for command‑and‑control communication, and has exploited known vulnerabilities in internet‑facing services such as unpatched Exchange servers as an initial access vector.

Attribution to the Iranian government is supported by Microsoft and other security firms, which link NEPTUNIUM’s infrastructure to Iranian hosting providers and note overlaps with IRGC‑aligned activity. The group’s domains, IP addresses, and malware artifacts have been traced to networks registered in Iran, reinforcing the state nexus. No public evidence connects NEPTUNIUM to criminal consortia or financially motivated cybercrime.

Notable campaigns attributed to NEPTUNIUM include the SpoofedScholars operation that used a compromised University of London site to target academics and journalists, a series of spear‑phishing attempts against defense contractors in 2020‑2021, the exploitation of CVE‑2020‑0609 in Internet Explorer to compromise energy‑sector targets, and repeated intrusion attempts against satellite and telecommunications providers to collect technical data. These operations have been documented in threat‑intelligence reports and demonstrate the group’s focus on sustained espionage rather than disruptive or financially driven outcomes.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB