logo

Iran's Elusive "SmudgedSerpent' APT Phishes Influential US Policy Wonks

ID: 8c4cf9c8-c4c5-5402-9c8c-cef0a6aebeaf

STIX ID: report--8c4cf9c8-c4c5-5402-9c8c-cef0a6aebeaf

Feed Name: Proofpoint Blog

Threat Score
85/100

Date Published: 2025-11-05

Date Updated: 2026-04-28

...
...

Between June and August 2025, researchers observed an Iran-aligned threat actor labeled UNK_SmudgedSerpent performing highly targeted phishing against US think-tank academics and policy experts to harvest Microsoft 365 credentials and deploy remote monitoring/management (RMM) software; the campaign's TTPs overlapped with multiple Iranian APTs (e.g., Charming Kitten/TA453, TA455, MuddyWater/TA450), creating attribution uncertainty and suggesting shared infrastructure, contractor support, or reorganized teams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.