logo

APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials

ID: 75564891-be04-538f-8180-e81682cc0032

STIX ID: report--75564891-be04-538f-8180-e81682cc0032

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Tushar Subhra Dutta

...
...

APT42 (Iran-linked) conducted a patient, AI-assisted spear-phishing campaign (SpearSpecter) targeting government and defense-related individuals using realistic personas and extended conversations to build trust, then delivered the TAMECAT infostealer via multiple delivery chains (WebDAV + PDF-themed .lnk, PowerShell, batch stages). The malware harvests browser cookies/credentials, mailbox data, screenshots, and files and exfiltrates via HTTPS/Discord/Telegram; the report includes detailed IoCs (domains, IPs, file hashes, registry keys), TTPs, and practical detection/mitigation recommendations such as session revocation and phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.