APT35 is a threat actor attributed to State-sponsored, Islamic Revolutionary Guard Corps (IRGC), assessed as information theft and espionage-motivated. Its recorded targeting runs to defense, education, energy, financial and adjacent sectors across 22 countries in the open reporting we hold — Kuwait, Saudi Arabia among them.
Across 78 attributed ATT&CK techniques we resolve 19 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are discovery command burst on one host and valid account abuse or account creation. Their toolkit is 13 named items: 3 we see only in this actor's reporting and 10 commodity or dual-use. That ratio is the point — the first group is what identifies them, the second is what they share with every other group and with red teams.
For a Gulf defender the relevant line is the victimology: Kuwait, Saudi Arabia appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.
As MITRE describes them: “FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government that conducts long term, resource-intensive operations to collect strategic intelligence. APT35 typically targets U.S. and the Middle Eastern military, diplomatic and government personnel, organizations in the media, energy and defense industrial base (DIB), and engineering, business services and telecommunications sectors.” — MITRE ATT&CK, CC BY 4.0.
On the name. “APT35” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.