#apt42 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #apt42, aggregated by home.social.
-
Iranian Hackers Target Defense and Government Officials in Ongoing Campaign https://www.securityweek.com/iranian-hackers-target-defense-and-government-officials-in-ongoing-campaign/ #Malware&Threats #Nation-State #SpearSpecter #espionage #APT42 #Iran
-
Iranian Hackers Target Defense and Government Officials in Ongoing Campaign https://www.securityweek.com/iranian-hackers-target-defense-and-government-officials-in-ongoing-campaign/ #Malware&Threats #Nation-State #SpearSpecter #espionage #APT42 #Iran
-
SpearSpecter: APT42-linked IRGC operators are conducting a sophisticated cyberespionage campaign targeting senior defense + government officials.
The campaign relies heavily on personalized social engineering, WhatsApp outreach, and the TAMECAT modular PowerShell backdoor using Discord/Telegram C2.
Full analysis:
https://www.technadu.com/spearspecter-cyberespionage-campaign-linked-to-iranian-irgc-targets-high-value-officials/613793/#APT42 #cyberespionage #IRGC #infosec #malwareanalysis #threatintel #technadu
-
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
#PROMPTFLUX #PROMPTSTEAL #TEMP_Zagros #UNC1069 #UNC4899 #APT42
https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools -
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
#PROMPTFLUX #PROMPTSTEAL #TEMP_Zagros #UNC1069 #UNC4899 #APT42
https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools -
APT42 impersonates cyber professionals to phish Israeli academics and journalists – Source: securityaffairs.com https://ciso2ciso.com/apt42-impersonates-cyber-professionals-to-phish-israeli-academics-and-journalists-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #Intelligence #hacking #Israel #APT42 #Iran #APT
-
APT42 impersonates cyber professionals to phish Israeli academics and journalists – Source: securityaffairs.com https://ciso2ciso.com/apt42-impersonates-cyber-professionals-to-phish-israeli-academics-and-journalists-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #Intelligence #hacking #Israel #APT42 #Iran #APT
-
"The office of Hannah Neumann, a member of the German Greens and head of the delegation spearheading work on European Union-Iran relations, was targeted by a hacking campaign that started in January, she said. Her staff was contacted with messages, phone calls and emails by hackers impersonating a legitimate contact. They eventually managed to target a laptop with malicious software.
"It was a very sophisticated attempt using various ways to manage that someone accidentally opens a link, including putting personal pressure on them," Neumann said.
Neumann was made aware of the ongoing ploy four weeks ago by the German domestic intelligence service, she said.
The group thought to be behind the attack is a hacking collective associated with the Iranian Revolutionary Guard, known as APT42, according to a report by the Parliament’s in-house IT service DG ITEC and seen by POLITICO. Another Iranian hacking group, called APT35 or Charming Kitten, was initially considered a culprit too. The two Iranian threat groups are closely related."
#EU #Germany #Iran #CyberSecurity #StateHacking #Spyware #APT42 #APT35
-
"The office of Hannah Neumann, a member of the German Greens and head of the delegation spearheading work on European Union-Iran relations, was targeted by a hacking campaign that started in January, she said. Her staff was contacted with messages, phone calls and emails by hackers impersonating a legitimate contact. They eventually managed to target a laptop with malicious software.
"It was a very sophisticated attempt using various ways to manage that someone accidentally opens a link, including putting personal pressure on them," Neumann said.
Neumann was made aware of the ongoing ploy four weeks ago by the German domestic intelligence service, she said.
The group thought to be behind the attack is a hacking collective associated with the Iranian Revolutionary Guard, known as APT42, according to a report by the Parliament’s in-house IT service DG ITEC and seen by POLITICO. Another Iranian hacking group, called APT35 or Charming Kitten, was initially considered a culprit too. The two Iranian threat groups are closely related."
#EU #Germany #Iran #CyberSecurity #StateHacking #Spyware #APT42 #APT35
-
APT42, eine Hackereinheit, die sehr wahrscheinlich von den iranischen Revolutionsgarden gesteuert wird, attackiert die Abgeordnete des EU-Parlaments und Leiterin der Iran-Delegation des EP, Hannah Neumann. Das ist Spionage, aber auch der Versuch, einzuschüchtern. #apt42
https://www.zeit.de/2025/17/hannah-neumann-spionage-iran-hacker-europaeisches-parlament -
APT42, eine Hackereinheit, die sehr wahrscheinlich von den iranischen Revolutionsgarden gesteuert wird, attackiert die Abgeordnete des EU-Parlaments und Leiterin der Iran-Delegation des EP, Hannah Neumann. Das ist Spionage, aber auch der Versuch, einzuschüchtern. #apt42
https://www.zeit.de/2025/17/hannah-neumann-spionage-iran-hacker-europaeisches-parlament -
Iranian cybercriminals are targeting WhatsApp users in spear phishing campaign https://www.malwarebytes.com/blog/news/2024/08/iranian-cybercriminals-are-targeting-whatsapp-users-in-spear-phishing-campaign #SocialEngineering #spearphishing #whatsapp #Scams #apt42 #News #iran
-
Iranian cybercriminals are targeting WhatsApp users in spear phishing campaign https://www.malwarebytes.com/blog/news/2024/08/iranian-cybercriminals-are-targeting-whatsapp-users-in-spear-phishing-campaign #SocialEngineering #spearphishing #whatsapp #Scams #apt42 #News #iran
-
#SocialEngineering: Meta blockiert verdächtige #WhatsApp-Konten | Security https://www.heise.de/news/Social-Engineering-Meta-blockiert-verdaechtige-WhatsApp-Konten-9846640.html #CyberCrime #Phishing #APT42 #UNC788 #MintSandstorm #MetaPlatforms
-
Google’s threat team confirms Iran targeting Trump, Biden, and Harris campaigns - Enlarge / Roger Stone, former adviser to Donald Trump's presidential ca... - https://arstechnica.com/?p=2043545 #threatanalysisgroup #presidentbiden #spearphishing #kamalaharris #donaldtrump #rogerstone #googletag #security #phishing #biz #google #apt42 #gmail #iran
-
Google’s threat team confirms Iran targeting Trump, Biden, and Harris campaigns - Enlarge / Roger Stone, former adviser to Donald Trump's presidential ca... - https://arstechnica.com/?p=2043545 #threatanalysisgroup #presidentbiden #spearphishing #kamalaharris #donaldtrump #rogerstone #googletag #security #phishing #biz #google #apt42 #gmail #iran
-
A Single #Iranian #Hacker Group Targeted Both Presidential Campaigns, #Google Says
#APT42 , which is believed to work for Iran’s #RevolutionaryGuard Corps, targeted about a dozen people associated with both Trump’s and Biden’s campaigns this spring, according to Google’s #ThreatAnalysisGroup.
#iran #trump #biden #election #election2024https://www.wired.com/story/iran-apt42-trump-biden-harris-phishing-targeting/
-
A Single #Iranian #Hacker Group Targeted Both Presidential Campaigns, #Google Says
#APT42 , which is believed to work for Iran’s #RevolutionaryGuard Corps, targeted about a dozen people associated with both Trump’s and Biden’s campaigns this spring, according to Google’s #ThreatAnalysisGroup.
#iran #trump #biden #election #election2024https://www.wired.com/story/iran-apt42-trump-biden-harris-phishing-targeting/
-
Iranian backed group steps up phishing campaigns against Israel, U.S.
#APT42
https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/ -
Why does no one talk about #APT42 propensity to bring a towel?
https://cloud.google.com/blog/topics/threat-intelligence/untangling-iran-apt42-operations/
-
Why does no one talk about #APT42 propensity to bring a towel?
https://cloud.google.com/blog/topics/threat-intelligence/untangling-iran-apt42-operations/
-
Uncharmed: Untangling Iran's APT42 Operations
#APT42 #TAMECAT #NICECURL
https://cloud.google.com/blog/topics/threat-intelligence/untangling-iran-apt42-operations/ -
📬 PowerLess: Malware hat es jetzt auch auf Telegram-Daten abgesehen
#Cyberangriffe #Kurznotiert #Malware #APT35 #APT42 #CharmingKitten #CheckPointResearch #EducatedManticore #MintSandstorm #Phosphorus #PowerLess #TA453 #Telegram https://tarnkappe.info/artikel/it-sicherheit/malware/powerless-malware-hat-es-jetzt-auch-auf-telegram-daten-abgesehen-273696.html -
📬 PowerLess: Malware hat es jetzt auch auf Telegram-Daten abgesehen
#Cyberangriffe #Kurznotiert #Malware #APT35 #APT42 #CharmingKitten #CheckPointResearch #EducatedManticore #MintSandstorm #Phosphorus #PowerLess #TA453 #Telegram https://tarnkappe.info/artikel/it-sicherheit/malware/powerless-malware-hat-es-jetzt-auch-auf-telegram-daten-abgesehen-273696.html -
CW: Thoughts on new #TA453/CharmingKitten Blog
What happens when a TA’s consistent TTPs change? Today we (#CristaNeedsAMastadon and I) released a blog detailing examples of weird and wacky techniques and targeting from #TA453.
https://www.proofpoint.com/us/blog/threat-insight/ta453-refuses-be-bound-expectations
With the current situation (#MahsaAmini) in Iran, I think it’s important to note that the Government of Iran (GOI) has had an intelligence interest in Gender Studies and Women’s Rights experts since AT LEAST 2021.
If we want to see how high they rank in interest, we just need to look at how they likely deployed the same malware (GhostEcho/CharmPower) against some of those researchers and activists that they did against Foreign Government embassy personnel.
When we pivot to look at Samantha, you see a persona that’s targeted MENA energy, a US based academic that’s an Iranian HVT, and senior US & European government officials, all using confrontational lures not typically seen from TA453.
Is this an actor gone rogue, willing to do anything to successfully phish at any cost? Maybe. Is it the intern or conscriptee just trying to meet a quota?
We don’t know but it’s definitely interesting to track.
We talked about confrontational conversational phishing, but nothing really says confrontational like compromising multiple email accounts just to deliver a JPEG of intimidation to a target. That, along with the compromise of a close affiliate of one of the former officials targeted in the IRGC Murder For Hire plot, leads us to believe that a subset of TA453 activity is more aggressive than we’ve seen historically.
Please go read it! Let us know what you think. #APT #Iran #IRGC #APT42 #Phosphorus #charmingKitten
-
CW: Thoughts on new #TA453/CharmingKitten Blog
What happens when a TA’s consistent TTPs change? Today we (#CristaNeedsAMastadon and I) released a blog detailing examples of weird and wacky techniques and targeting from #TA453.
https://www.proofpoint.com/us/blog/threat-insight/ta453-refuses-be-bound-expectations
With the current situation (#MahsaAmini) in Iran, I think it’s important to note that the Government of Iran (GOI) has had an intelligence interest in Gender Studies and Women’s Rights experts since AT LEAST 2021.
If we want to see how high they rank in interest, we just need to look at how they likely deployed the same malware (GhostEcho/CharmPower) against some of those researchers and activists that they did against Foreign Government embassy personnel.
When we pivot to look at Samantha, you see a persona that’s targeted MENA energy, a US based academic that’s an Iranian HVT, and senior US & European government officials, all using confrontational lures not typically seen from TA453.
Is this an actor gone rogue, willing to do anything to successfully phish at any cost? Maybe. Is it the intern or conscriptee just trying to meet a quota?
We don’t know but it’s definitely interesting to track.
We talked about confrontational conversational phishing, but nothing really says confrontational like compromising multiple email accounts just to deliver a JPEG of intimidation to a target. That, along with the compromise of a close affiliate of one of the former officials targeted in the IRGC Murder For Hire plot, leads us to believe that a subset of TA453 activity is more aggressive than we’ve seen historically.
Please go read it! Let us know what you think. #APT #Iran #IRGC #APT42 #Phosphorus #charmingKitten
-
⚠ #HRW and #Amnesty investigation reveals #Iran gov't backed hackers have targeted activists, journalists, & researchers working on Middle East issues with phishing attacks.
@humanrightswatch infosec team attributes this campaign to state-backed threat actor #APT42.
I spent the past couple of weeks with @tek and @donncha investigating an ongoing social engineering and phishing campaign that impersonated a think tank based in #Lebanon to trick its targets and invite them to a summit.
2 HRW staff were targeted, and after investigating the infrastructure used, we found 18 other targets. at least 3 targets were successfully compromised by #APT42
Read the full report and the technical analysis on HRW's website 👇
https://www.hrw.org/news/2022/12/05/iran-state-backed-hacking-activists-journalists-politicians
-
⚠ #HRW and #Amnesty investigation reveals #Iran gov't backed hackers have targeted activists, journalists, & researchers working on Middle East issues with phishing attacks.
@humanrightswatch infosec team attributes this campaign to state-backed threat actor #APT42.
I spent the past couple of weeks with @tek and @donncha investigating an ongoing social engineering and phishing campaign that impersonated a think tank based in #Lebanon to trick its targets and invite them to a summit.
2 HRW staff were targeted, and after investigating the infrastructure used, we found 18 other targets. at least 3 targets were successfully compromised by #APT42
Read the full report and the technical analysis on HRW's website 👇
https://www.hrw.org/news/2022/12/05/iran-state-backed-hacking-activists-journalists-politicians